NoteDiscovery is a self-hosted app. Please report vulnerabilities privately so they can be fixed before they are discussed in public.
Use GitHub's private vulnerability reporting on this repository. That creates a private draft advisory — a private conversation with me, not a public disclosure.
Do not open a public issue with technical details, proof-of-concept code, or payloads.
Include:
- NoteDiscovery version (or commit) you tested
- A short description of the issue
- Steps to reproduce on a local instance
- What an attacker could do with it
In scope: security bugs in NoteDiscovery itself (latest release).
Out of scope: deployment/configuration issues (for example exposing an instance to the internet without auth), social engineering, and findings that only affect third-party plugins or unmodified upstream dependencies.
This is a spare-time hobby project. I will acknowledge the report when I can. Draft advisories stay private: I will not request CVE IDs or publish public security advisories. If the issue is valid, I will fix it and include it in a normal release.
Please do not disclose it publicly until a release is out, or until we agree otherwise.
Thanks for reporting issues responsibly.