Security Policy

Reporting Security Vulnerabilities

We take security seriously at PasteFox. If you discover a security vulnerability, please report it responsibly by emailing us at [email protected].

What to Include

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact of the vulnerability
  • Any suggestions for fixing the issue (optional)

Our Commitment

  • We will acknowledge receipt within 48 hours
  • We will investigate and validate the report
  • We will keep you informed of our progress
  • We will not take legal action against researchers acting in good faith

Scope

The following are in scope:

  • pastefox.com and all subdomains
  • API endpoints at pastefox.com/api/*
  • Authentication and authorization issues
  • Data exposure vulnerabilities
  • Cross-site scripting (XSS)
  • SQL injection
  • Remote code execution

Out of Scope

  • Denial of Service (DoS) attacks
  • Social engineering attacks
  • Physical security issues
  • Issues in third-party services
  • Spam or phishing

Preferred Languages

German, English