Security Disclosure
How to report vulnerabilities in Cosmopedia. Machine-readable copy at /.well-known/security.txt.
Reporting
Email [email protected]. For non-security questions, use the contact form.
Please include reproduction steps, affected URL or endpoint, browser/agent, and any logs you have. If the issue is sensitive, request a PGP key in your first message and we will respond out-of-band.
Response timeline
- 72h: initial acknowledgement.
- 7d: severity assessment and patch plan or risk acceptance.
- 30d: public disclosure once a fix is deployed, unless the reporter prefers earlier.
Scope
In scope:
- cosmopedia.xyz and its subdomains.
- /api/v1/* REST endpoints, /mcp MCP server, /api/feed/* feeds.
- The metrics endpoint (/api/metrics).
Out of scope:
- Rate-limit volume tests, denial-of-service, automated scanners.
- Issues only reproducible with a custom client that disables CSP or modifies bundled JS.
- Reports based on missing security headers without a concrete exploit.
- Third-party services we depend on (OpenAI, GitHub, cosmos.directory) - report those upstream.
Safe harbour
Good-faith research on this scope, conducted without privacy or availability damage, will not lead to legal action. Please avoid touching production data of other users (IPs).
Acknowledgements
No reports received yet. Future reporters who opt-in will be credited here with name + GitHub/Twitter handle.