Security is a priority across every Nomploy project. We appreciate the help of security researchers and the community in finding and reporting vulnerabilities.
Email contact@nomploy.com. Please do not open a public issue for a suspected vulnerability.
Include as much as you can:
- a description of the issue and the component or repository it affects,
- steps to reproduce it,
- sample code, screenshots or a short recording if they help,
- the impact you think it has, and the version or commit you tested.
We will acknowledge your report as quickly as we can and keep you updated while we investigate. Time to a fix depends on complexity and severity.
- Do not access user data or systems beyond what is needed to demonstrate the issue.
- Do not run denial-of-service tests, spam or social engineering.
- Do not modify or destroy data that is not yours.
- Give us a reasonable window to ship a fix before disclosing publicly.
Fixes land on the latest release of the affected project. If you are running a self-hosted instance, upgrade to the current version before reporting — the issue may already be fixed.