Skip to content

Security: boxcreate/avatarlab

Security

SECURITY.md

Security

Reporting a vulnerability

Please do not open a public issue for security-sensitive findings.

Email boxlore@aswin.cx with:

  • A clear description of the issue
  • Reproduction steps
  • The affected browser, platform, or export format
  • Any proof-of-concept files required to verify it

You should receive an acknowledgement within seven days.

Scope

avatar lab is currently a frontend-only application. Drafts are stored in browser local storage and the editor does not require an account. Reports involving dependency vulnerabilities, unsafe generated code, SVG/XML injection, or exported asset handling are in scope.

There aren't any published security advisories