Responsible Disclosure

AliasVault takes security seriously and encourages responsible disclosure of security vulnerabilities.

  • Home
  • Responsible Disclosure

We appreciate the work of security researchers and ethical hackers who help keep AliasVault and our users secure. If you believe you have discovered a security vulnerability in AliasVault, we encourage you to report it to us responsibly.

Please report security vulnerabilities to:

security@support.aliasvault.net

Commitment

We take responsible disclosure of security vulnerabilities seriously. Where applicable, we will:

  • Acknowledge receipt of your report within 48 hours
  • Investigate and validate the reported vulnerability
  • Provide regular updates on our progress
  • Credit you in our security advisory (if desired)
  • Submit for CVE assignment when applicable
  • Coordinate disclosure timeline with you

Disclosure Guidelines

To ensure the safety of our users and systems, please follow these guidelines:

  • Do not access, modify, or delete user data
  • Use minimal interaction necessary to demonstrate the vulnerability
  • Keep vulnerability details confidential until coordinated disclosure
  • Do not violate any applicable laws or regulations
  • Test only against systems you own (self-hosted) or have explicit permission to test

Scope

This policy applies to the AliasVault main application (app.aliasvault.net) and API endpoints. Social engineering, physical attacks, denial of service, spam, and automated scanning without prior approval are typically considered out of scope.

Hall of Fame

This Hall of Fame consists of security researchers who have helped make AliasVault more secure by responsibly disclosing vulnerabilities in the past. We recognize and thank these researchers for their valuable contributions:

Filippo Decortes(Bitcube Security)

September 19, 2025

highCVE-2025-59344

Server-Side Request Forgery (SSRF) vulnerability in favicon extraction feature allowing internal network scanning and limited data exfiltration in AliasVault API versions ≀0.23.0

View AdvisoryGHSA-f253-f7xc-w7pj