Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Security: MagicMirrorOrg/MagicMirror

.github/SECURITY.md

Security Policy

Scope and Deployment

MagicMirror is primarily intended for trusted local/private network environments. Direct public exposure to the internet or other untrusted networks is not recommended.

We take security seriously and encourage responsible disclosure of vulnerabilities to help us improve the software.

Reporting a Vulnerability

Please keep vulnerability details private — do not post them in public GitHub issues.

Instead, reach out privately via the MagicMirror forum to one of the core developers:

Please include, if possible:

  • Affected version(s)
  • Reproduction steps or proof-of-concept
  • What could an attacker do with this?
  • Any ideas how to fix it?

Coordinated Disclosure

We will keep reported vulnerabilities private until a fix is available and coordinate the disclosure timeline with you. We aim to respond as quickly as possible.

Learn more about advisories related to MagicMirrorOrg/MagicMirror in the GitHub Advisory Database
Morty Proxy This is a proxified and sanitized view of the page, visit original site.