FileMorph takes security seriously. This document describes how to report a
vulnerability and what response you can expect. The same policy is mirrored at
/security
in any running deployment, and discoverable via
/.well-known/security.txt on
each instance.
There has been one tagged release so far: v1.1.0 (tagged 2026-06-01). Security fixes
are made on the main branch, which has moved on since that tag; the latest
and office container images are rebuilt from main on every merge. Older
tags receive fixes only when the issue is critical and the upgrade path is
non-trivial; otherwise users are expected to upgrade to the newest release or
main.
Email security@filemorph.io. Encrypted mail is welcome — request our PGP
key at the same address. Please do not file vulnerability reports as public
GitHub issues.
- A description of the vulnerability and its potential impact.
- Steps to reproduce, with any required configuration or input files.
- Affected version (commit hash or release tag if known).
- Whether the issue has already been disclosed publicly elsewhere.
| Stage | Target |
|---|---|
| Acknowledgement | within 72 hours of receipt |
| Initial triage + severity | within 7 days |
| Critical fix released | within 7 days of triage |
| High-severity fix released | within 30 days |
| Medium / low | fixed on main; part of the next tagged release |
We publish an advisory once a fixed release is available and credit the reporter unless they request otherwise.
These targets apply to vulnerability reports from anyone, paid or not.
Compliance Edition licensees can additionally contract a support SLA for
non-security issues (deployment, configuration, defects) — the framework is in
docs/support-sla.md, the figures are set per agreement.
A paid SLA buys priority attention; it does not change the security-fix clock
above, which applies to everyone.
In scope:
- The FileMorph application source in this repository.
- Official Docker images and release artifacts published by the maintainers.
- Documented API endpoints and the bundled web UI.
Out of scope:
- Third-party services FileMorph depends on (Stripe, Zoho, Cloudflare, Hetzner). Please report to those vendors directly.
- Issues that require physical access to a self-hosted server, or social engineering of an operator.
- Reports generated only by automated scanners without a working proof-of-concept.
- Self-hoster-specific deployment misconfiguration not caused by our defaults or documentation.
Good-faith research in line with this policy will not result in legal action from the FileMorph project. Please avoid privacy violations, service disruption, and destruction of data; test against your own self-hosted instance whenever possible.