AliasVault takes security seriously and encourages responsible disclosure of security vulnerabilities.
We appreciate the work of security researchers and ethical hackers who help keep AliasVault and our users secure. If you believe you have discovered a security vulnerability in AliasVault, we encourage you to report it to us responsibly.
Please report security vulnerabilities to:
security@support.aliasvault.netWe take responsible disclosure of security vulnerabilities seriously. Where applicable, we will:
To ensure the safety of our users and systems, please follow these guidelines:
This policy applies to the AliasVault main application (app.aliasvault.net) and API endpoints. Social engineering, physical attacks, denial of service, spam, and automated scanning without prior approval are typically considered out of scope.
This Hall of Fame consists of security researchers who have helped make AliasVault more secure by responsibly disclosing vulnerabilities in the past. We recognize and thank these researchers for their valuable contributions:
September 19, 2025
Server-Side Request Forgery (SSRF) vulnerability in favicon extraction feature allowing internal network scanning and limited data exfiltration in AliasVault API versions β€0.23.0