Security reports are welcome.
If you believe you found a vulnerability in Claude2PDF, please report it privately instead of opening a public GitHub issue.
Send the report to:
Please include, when possible:
- A clear description of the issue
- Steps to reproduce it
- The affected URL, route, or component
- Expected behavior
- Actual behavior
- Screenshots, logs, or proof of concept
- Any suggested mitigation, if you have one
Please do not include credentials, session tokens, cookies, private conversations, or personal data that does not belong to you.
When testing Claude2PDF, please:
- Only test accounts, data, and public share links you are authorized to use
- Avoid disrupting the service
- Avoid accessing or attempting to access data belonging to other users
- Avoid destructive testing
- Avoid automated scanning that could significantly affect service availability
- Do not publicly disclose a vulnerability before there has been reasonable time to investigate and address it
Good-faith security research performed within these boundaries is appreciated.
Reports related to the following are especially useful:
- Server-side request handling
- Public share URL validation
- Provider extraction logic
- HTML sanitization
- Cross-site scripting
- Injection vulnerabilities
- Access control issues
- Sensitive data exposure
- Unsafe redirects
- Dependency vulnerabilities with a practical impact on Claude2PDF
Issues that only affect unsupported browser extensions, modified local deployments, or third-party AI platforms themselves may fall outside the scope of this project.
I will make a reasonable effort to:
- Acknowledge valid reports
- Investigate reproducible security issues
- Fix confirmed vulnerabilities as appropriate
- Keep reporters updated when practical
There is currently no formal bug bounty program.
Please use normal GitHub issues for bugs that do not involve security or sensitive information.
If you are unsure whether something is security-sensitive, email it privately first.