If you discover a security vulnerability in Applika, please do not open a public issue.
Instead, report it by creating a GitHub Issue and mark it as a security report in the title (e.g. [Security] ...).
We will acknowledge the report within 72 hours and aim to resolve confirmed vulnerabilities as quickly as possible.
The following are in scope:
- Authentication and session handling
- Authorization bypasses
- Data exposure or leakage
- API security issues
- Denial of service attacks
- Issues in third-party dependencies without a working proof of concept
- Social engineering
English and Portuguese (pt-BR) are both accepted.