If you discover a security vulnerability in OmniResearch, please report it privately rather than opening a public issue or pull request. Public disclosure before a fix is available puts every user of the deployed application at risk.
Contact: elhammemi001@gmail.com
When reporting, please include as much of the following as you can:
- A description of the vulnerability and its potential impact
- Steps to reproduce it, or a proof of concept
- The affected component (frontend, backend, a specific endpoint, dependency, etc.)
- Any suggested remediation, if you have one
- You will receive an acknowledgment of your report as soon as possible.
- The issue will be investigated and, if confirmed, a fix will be prioritized.
- You will be kept informed of progress until the issue is resolved.
- Once a fix is in place, you're welcome to ask about public disclosure timing.
This policy covers the OmniResearch codebase in this repository (backend and frontend). Please do not test against any deployed/hosted instance you do not own without prior written permission.
Thank you for helping keep OmniResearch and its users safe.