Security fixes are applied to the current production release on the main
branch. Older commits and preview deployments are not supported releases.
Email pes1ug23cs165@pesu.pes.edu with the subject
CPBoard security report. Do not open a public issue or discussion for a
suspected vulnerability.
Include, when possible:
- the affected URL, endpoint, or commit;
- clear reproduction steps and the security impact;
- a minimal proof of concept with sensitive values removed;
- whether any account or user data may have been accessed; and
- a safe way to contact you for follow-up.
If a credential is exposed, report only its name and where it was found. Do not send the credential itself. The project will aim to acknowledge reports within three business days and will coordinate disclosure after a fix is available.
Please use your own account and data. Do not:
- access, alter, or retain another person's data;
- perform denial-of-service, spam, social-engineering, or physical attacks;
- run destructive database or account operations;
- degrade upstream competitive-programming services; or
- publish a vulnerability before remediation has been coordinated.
Stop testing and report immediately if you encounter secrets, private data, or access beyond what is needed to demonstrate the issue. This project does not currently operate a paid bug-bounty program.