Skip to content

Security: OpenHW-Studio/OpenHW-studio--cli

Security

SECURITY.md

Security Policy

Supported Versions

We actively maintain and patch security vulnerabilities for the following versions of OpenHW-Studio:

Version Supported
Latest (main branch) ✅ Yes
Previous minor release ✅ Yes
Older releases ❌ No

Reporting a Vulnerability

Please do NOT report security vulnerabilities through public GitHub issues.

If you discover a security vulnerability in OpenHW-Studio, please report it responsibly by following these steps:

1. Send a Private Report

Email our security team at:

📧 support@fossee.in

Use the subject line: [SECURITY] Vulnerability Report - OpenHW-Studio

2. Include the Following Information

  • A description of the vulnerability
  • The affected repository and component
  • Steps to reproduce the issue
  • Potential impact and severity
  • Any suggested fix (optional but appreciated)

3. What Happens Next

  • You will receive an acknowledgment within 48 hours
  • We will investigate and assess the severity within 5 business days
  • We will work on a fix and keep you updated on progress
  • We will publicly disclose the vulnerability after a fix is released and deployed
  • We will credit you in the security advisory (unless you prefer to remain anonymous)

Scope

The following are in scope for security reports:

  • Authentication & Authorization issues (login, sessions, tokens, permissions)
  • Data exposure — sensitive user or project data being leaked
  • Remote code execution vulnerabilities
  • Cross-site scripting (XSS) or Cross-site request forgery (CSRF)
  • Injection attacks (SQL, NoSQL, command injection)
  • Simulation sandbox escape — breaking out of the browser-side simulation
  • API security issues (rate limiting bypass, unauthorized access)

The following are out of scope:

  • Denial of Service (DoS) attacks
  • Issues in third-party dependencies that are not yet patched upstream
  • Physical attacks
  • Social engineering
  • Issues in development/local environments

Responsible Disclosure Policy

We follow a coordinated disclosure approach:

  1. Reporter submits the vulnerability privately
  2. We confirm and assess the issue
  3. We develop and test a fix
  4. We release the fix in a security patch
  5. We publicly disclose the vulnerability details (CVE if applicable)

We ask that you:

  • Give us reasonable time to fix the issue before public disclosure
  • Do not exploit the vulnerability beyond what is necessary to demonstrate it
  • Do not access, modify, or delete data that does not belong to you

Contact

📧 Security Email: support@fossee.in
🌐 Website: fossee.in
🏛️ Organization: FOSSEE Project, IIT Bombay

There aren't any published security advisories