Skip to content

Security: RRRTX-Labs/LearnPath

Security

SECURITY.md

Security Policy

Reporting

Please report vulnerabilities privately via GitHub Security Advisories. Do not open a public issue for exploitable bugs.

Scope

  • Authentication and session handling
  • XSS in notes, reports, or Markdown
  • Privilege escalation on /admin
  • Sandbox escapes in the practice engines

Out of scope

  • YouTube’s own player
  • Third-party resource sites
  • Social engineering of Discord members

Rules we will not violate to “help”

We will not add video downloaders, custom YouTube players, or server-side execution of untrusted code.

There aren't any published security advisories