We actively maintain and patch security vulnerabilities for the following versions of OpenHW-Studio:
| Version | Supported |
|---|---|
Latest (main branch) |
✅ Yes |
| Previous minor release | ✅ Yes |
| Older releases | ❌ No |
Please do NOT report security vulnerabilities through public GitHub issues.
If you discover a security vulnerability in OpenHW-Studio, please report it responsibly by following these steps:
Email our security team at:
Use the subject line: [SECURITY] Vulnerability Report - OpenHW-Studio
- A description of the vulnerability
- The affected repository and component
- Steps to reproduce the issue
- Potential impact and severity
- Any suggested fix (optional but appreciated)
- You will receive an acknowledgment within 48 hours
- We will investigate and assess the severity within 5 business days
- We will work on a fix and keep you updated on progress
- We will publicly disclose the vulnerability after a fix is released and deployed
- We will credit you in the security advisory (unless you prefer to remain anonymous)
The following are in scope for security reports:
- Authentication & Authorization issues (login, sessions, tokens, permissions)
- Data exposure — sensitive user or project data being leaked
- Remote code execution vulnerabilities
- Cross-site scripting (XSS) or Cross-site request forgery (CSRF)
- Injection attacks (SQL, NoSQL, command injection)
- Simulation sandbox escape — breaking out of the browser-side simulation
- API security issues (rate limiting bypass, unauthorized access)
The following are out of scope:
- Denial of Service (DoS) attacks
- Issues in third-party dependencies that are not yet patched upstream
- Physical attacks
- Social engineering
- Issues in development/local environments
We follow a coordinated disclosure approach:
- Reporter submits the vulnerability privately
- We confirm and assess the issue
- We develop and test a fix
- We release the fix in a security patch
- We publicly disclose the vulnerability details (CVE if applicable)
We ask that you:
- Give us reasonable time to fix the issue before public disclosure
- Do not exploit the vulnerability beyond what is necessary to demonstrate it
- Do not access, modify, or delete data that does not belong to you
📧 Security Email: support@fossee.in
🌐 Website: fossee.in
🏛️ Organization: FOSSEE Project, IIT Bombay