Skip to content

Security: Vedant01/Karma-Protocol

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.x.x ✅ Yes

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

If you discover a security vulnerability in KARMA Protocol, please report it responsibly:

  1. Email: security@karmaprotocol.io
  2. Subject: [SECURITY] Brief description
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

We will acknowledge receipt within 48 hours and provide a detailed response within 7 days, including our planned remediation timeline.

What to Expect

  • We will keep you informed of the progress toward a fix
  • We will credit you in the release notes (unless you prefer anonymity)
  • We ask that you do not publicly disclose the vulnerability until we have released a fix

Scope

The following are in scope:

  • API authentication bypass
  • SQL injection or data exposure
  • API key leakage
  • Score manipulation via crafted eval submissions
  • XSS in the dashboard

The following are out of scope:

  • Issues in third-party dependencies (report to them directly)
  • Rate limiting bypasses in local development setup
  • Issues requiring physical access to the server

There aren't any published security advisories