Skip to content
LibxaFrame
Sign In

Security Policy

How to report a vulnerability, and what is worth reporting.

Last updated 9 August 2026

Reporting a vulnerability

Do not open a public issue. Use GitHub's private vulnerability reporting on the relevant repository: Security → Report a vulnerability, or email security@vyloxi.com.

Please include what an attacker can achieve, the steps to reproduce it, and the version you tested. You will get an acknowledgement within three working days.

We will not take legal action against anyone acting in good faith to find and report a vulnerability, provided you do not access data that is not yours, do not degrade the service for others, and give us a reasonable window to fix the issue before disclosing it.

Supported versions

Pre-1.0, only the latest minor line receives fixes. Libxa Desktop updates itself, so running an old build is a choice rather than a constraint.

What is worth reporting

LibxaFrame is a web framework, so anything that lets a request escape its boundaries: authentication or authorisation bypass, SQL injection through the Atlas query builder, template injection, CSRF token weaknesses, session fixation, an open redirect, or a path traversal in view or asset resolution.

Libxa Desktop has more reach than a typical desktop app, and each of these is a high-severity report:

  • A way to bypass the checksum verification on a runtime download, or to get the app to execute a binary it did not verify.
  • A way to make the app write outside its marked block in the hosts file, or to abuse the elevated copy step to write somewhere else.
  • Anywhere a project-controlled string reaches a command line: a directory name, a site name, a value from composer.json.
  • A way for the renderer to escape the preload bridge and reach Node or the filesystem directly.
  • A way to reach files outside a site's document root through the generated nginx configuration.

What is already known

Two things are documented rather than secret, so please do not report them as findings:

  • Desktop builds are not code-signed. Windows SmartScreen warns on first install. This is a missing certificate; it does not weaken the checksum verification.
  • Sites are served on all network interfaces. On an untrusted network, others on that network can reach them. That is what a local web server does. phpMyAdmin is the exception and is bound to localhost, because it administers the database as root.

How releases are protected

Installers are published by a GitHub Actions workflow that builds from a tag, into a repository that holds nothing but build artifacts. The updater verifies every download against the SHA-512 in latest.yml, which is generated by the same build that produced the installer, and a pre-publish check refuses a release whose manifest does not describe its own binary.

Renderer hardening

Libxa Desktop's UI runs with contextIsolation: true, nodeIntegration: false, a content security policy with no remote or inline script, and no direct access to Node. Every capability is an explicit, typed method on the preload bridge. Anything that lets the renderer step outside that bridge is a vulnerability regardless of what it achieves.