If you believe you've found a security vulnerability in any repository under the LexiSmash organization (the game, the dictionary data, the Explorer website, or anything else), please report it privately rather than opening a public Issue, Discussion, or Pull Request.
Please send an email to f.rombaldoni@campus.uniurb.it instead of using public GitHub Issues, Discussions, or Pull Requests.
Please include as much of the following as you can, to help triage the report faster:
- Type of issue (e.g. cross-site scripting, authentication/authorization bypass, exposed credentials, data exposure, a dependency with a known vulnerability)
- Which repository and, if known, the affected file(s), commit, branch, or tag
- Step-by-step instructions to reproduce the issue
- Proof-of-concept code, if applicable
- Potential impact, and how it could be exploited
This is a personal, unpaid open source project — there is no bug bounty program and no monetary reward for reports. Valid reports will be acknowledged, fixed as soon as reasonably possible, and credited in the fix unless you'd rather stay anonymous.