Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Reporting a vulnerability

Found a way for the server, or anyone else, to learn something it shouldn’t? Please report it privately through GitHub’s private vulnerability reporting, not a public issue.

Include:

  • what an attacker can do, and from where (a malicious server, another user, someone with a public link, a web page);
  • steps or a proof of concept;
  • the commit or release you tested.

We’ll reply within a week. Please give us a reasonable time to fix it before publishing.

In scope, for example:

  • anything that lets the server or anyone else learn plaintext names, contents, keys or passwords;
  • a malicious server swapping, reordering or truncating ciphertext without the client noticing;
  • a shared file or public link that runs script in the app’s origin;
  • reaching nodes you don’t own and weren’t shared.

The known limitations aren’t vulnerabilities in themselves.