Security fixes are applied to the latest main branch state.
Please report vulnerabilities privately before public disclosure.
Preferred channels:
- GitHub Security Advisories for this repository.
- E-mail:
security@informigados.com.br
Include:
- Clear impact description.
- Reproduction steps or proof of concept.
- Affected files/endpoints.
- Suggested mitigation (if available).
Pixel Forge enforces:
- Local-only architecture by default.
- Host header validation.
- Security response headers.
- Path access restrictions for preview/open operations.
- Filename sanitization and controlled temporary directories.