Skip to content

Security: Daziusm/maryl

Security

SECURITY.md

Security policy

Supported versions

Version Supported
main Yes

Reporting a vulnerability

Do not open a public GitHub issue for security problems.

Use GitHub private vulnerability reporting if available, or contact the repository owner with:

  • Description of the issue and impact
  • Steps to reproduce
  • Affected version / commit

You should receive a response within a reasonable timeframe. We will coordinate disclosure and credit if you want it.

Scope

In scope: authentication bypass, authorization flaws, remote code execution via the panel, Docker escape via panel-controlled options, secret leakage through API responses.

Out of scope: denial of service against your own panel without a specific bug, misconfiguration of Docker socket permissions on the host, brute force when login rate limits are disabled by running a modified build.

There aren't any published security advisories