| Version | Supported |
|---|---|
| 0.x.x | ✅ Yes |
Please do not report security vulnerabilities through public GitHub issues.
If you discover a security vulnerability in KARMA Protocol, please report it responsibly:
- Email: security@karmaprotocol.io
- Subject:
[SECURITY] Brief description - Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We will acknowledge receipt within 48 hours and provide a detailed response within 7 days, including our planned remediation timeline.
- We will keep you informed of the progress toward a fix
- We will credit you in the release notes (unless you prefer anonymity)
- We ask that you do not publicly disclose the vulnerability until we have released a fix
The following are in scope:
- API authentication bypass
- SQL injection or data exposure
- API key leakage
- Score manipulation via crafted eval submissions
- XSS in the dashboard
The following are out of scope:
- Issues in third-party dependencies (report to them directly)
- Rate limiting bypasses in local development setup
- Issues requiring physical access to the server