Skip to content

Security: Sydney-Elvis/M3Undle

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in M3Undle, please report it privately.

  • Open a private vulnerability report via GitHub (preferred), or
  • Email:

Please include:

  • Description of the issue
  • Steps to reproduce
  • Affected endpoints (e.g. M3U, XMLTV, HDHR)
  • Any relevant logs or requests

What to Expect

  • I will acknowledge receipt within 48 hours
  • I will work to validate and address the issue as quickly as possible
  • You may be asked for additional details during investigation

Disclosure Policy

Please do not publicly disclose the issue until:

  • A fix has been released, or
  • We agree on a disclosure timeline

Scope

This project includes:

  • IPTV proxy endpoints (M3U, XMLTV, HDHR)
  • Web UI and API endpoints
  • Authentication and access control

Notes

This is an early-stage project. Security improvements are ongoing, and responsible disclosure is appreciated.

There aren’t any published security advisories