If you believe you have found a security issue in openmediavault, contact us at security [at] openmediavault [dot] org.
Please do not disclose security issues publicly until we publish a fix and announce a security release.
Please include the following information in your report:
- A clear description of the vulnerability and its potential impact.
- Steps to reproduce the issue.
- Affected versions, packages or components.
- Any mitigation ideas or patches you may already have.
- AI-assisted reports are acceptable only if they are human-verified, technically accurate and reproducible.
- A valid reporter name that can be used for attribution.
- Explicit consent that this reporter name may be used for acknowledgements in commits and changelogs.
Reports missing required information may delay triage and response.
- Issues or bugs that aren't security related.
- Issues that are related to the underlying operating system or third-party software (e.g. Debian, PHP, Python, Samba, NGINX, ...).
- Issues that can only be exploited by the administrator itself (the admin is already a privileged user and implicitly trusted).