We take security seriously and appreciate responsible disclosure of vulnerabilities.
| Version | Supported |
|---|---|
| 1.x | ✅ |
| 0.x | ❌ |
Please do not report security vulnerabilities through public GitHub issues.
If you think you have found a security issue, report it privately in one of two ways:
- Use GitHub's private reporting: Report a vulnerability (Security tab → "Report a vulnerability")
- Send the details to support@tabler.io
Please include:
- A descriptive title
- A description of the issue and its potential impact
- Steps to reproduce, or a proof of concept if possible
- The affected version(s)
We will review your report and get back to you as soon as possible. Please give us reasonable time to address the issue before disclosing it publicly.
unstroke parses untrusted SVG. Input that makes the parser or the geometry
pipeline hang, allocate without bound or crash the process is in scope, as is
anything that lets crafted input write outside the requested output location
when using the CLI.