Security Policy
Reporting Security Vulnerabilities
We take security seriously at PasteFox. If you discover a security vulnerability, please report it responsibly by emailing us at [email protected].
What to Include
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact of the vulnerability
- Any suggestions for fixing the issue (optional)
Our Commitment
- We will acknowledge receipt within 48 hours
- We will investigate and validate the report
- We will keep you informed of our progress
- We will not take legal action against researchers acting in good faith
Scope
The following are in scope:
- pastefox.com and all subdomains
- API endpoints at pastefox.com/api/*
- Authentication and authorization issues
- Data exposure vulnerabilities
- Cross-site scripting (XSS)
- SQL injection
- Remote code execution
Out of Scope
- Denial of Service (DoS) attacks
- Social engineering attacks
- Physical security issues
- Issues in third-party services
- Spam or phishing
Preferred Languages
German, English