We take the security of Lexbor seriously. If you discover a security vulnerability in this project, please do not create a public issue. Also remember that not all bugs are vulnerabilities, and not all bugs can be exploited.
If you are really sure that there is a vulnerability issue:
- Use the [Report a vulnerability] button on our GitHub Advisories page to submit a private report.
- Alternatively, you can send an email directly to the maintainer at [support@lexbor.com].
Please include the following information in your report:
- A description of the vulnerability and its impact.
- Steps to reproduce the issue (including any PoC code or malformed HTML/CSS/Font/URL etc.).
- The version(s) of Lexbor affected.
We will acknowledge receipt of your vulnerability report within [48 hours] and strive to send you regular updates about our progress. If the vulnerability is accepted, we will coordinate with you on publishing a Security Advisory and requesting a CVE ID.