Skip to content

Security: Letdown2491/hanami

SECURITY.md

Security Policy

hanami is a self-hosted media server that handles private keys' signatures, encrypted files, and untrusted network input, so security reports are taken seriously and are welcome.

Supported versions

hanami is pre-1.0 and ships from main. Security fixes land on main and in the next tagged release; there is no back-porting to older tags. Always run the latest release.

Version Supported
latest release / main ✅
older tags ❌

Reporting a vulnerability

Please do not open a public issue for a security vulnerability.

Report it privately through GitHub's Report a vulnerability button (repository → Security → Advisories). This opens a private advisory visible only to you and the maintainer.

In your report, please include:

  • affected version / commit,
  • a description of the issue and its impact,
  • steps to reproduce (a proof of concept if you have one),
  • any suggested fix.

You can expect an initial acknowledgement within a few days. Once a fix is ready we'll coordinate a disclosure timeline with you and credit you in the advisory unless you'd rather stay anonymous.

Scope

hanami's full trust model, security guarantees, and known limitations are documented in docs/threat-model.md. This section summarizes what is most worth reporting.

Things that are in scope and especially worth reporting:

  • authentication / session handling and the dashboard's access control,
  • the Blossom server (upload/serve/delete authorization, BUD auth),
  • private-file encryption and the encrypted drive (key handling, decrypt-and-serve),
  • SSRF and request forwarding (member-supplied server URLs, mirror/repair fetches, allowed_hosts / trusted_proxies),
  • the federation peer backup path,
  • anything that lets one member read or modify another member's data.

Because hanami is self-hosted, an operator who deliberately misconfigures their own instance (e.g. serving plaintext HTTP on a public interface, which hanami already warns about at startup) is out of scope, but a report that hanami's defaults are unsafe is very much in scope.

Thank you for helping keep hanami and the people who run it safe.

Learn more about advisories related to Letdown2491/hanami in the GitHub Advisory Database