| Version | Supported |
|---|---|
Latest (main) |
✅ |
| Older branches | ❌ |
Qute is a security tool — we take vulnerabilities seriously.
Please do not report security vulnerabilities via public GitHub issues. This gives time for a fix to be prepared before the vulnerability is publicly known.
Instead, please report vulnerabilities by emailing the maintainer directly. You can find contact details on the GitHub profile associated with this repository.
Please include in your report:
- A description of the vulnerability and its potential impact
- Steps to reproduce, or a proof-of-concept if available
- The version or commit where you observed the issue
- Any suggested mitigations if you have them
You should receive an acknowledgement within 48 hours and a more detailed response within 7 days outlining next steps.
Security reports are welcome for:
- Vulnerabilities in Qute's own code (injection, auth bypass, data exposure)
- Issues with the syslog listener or replay generator that could be exploited
- DuckDB query injection via crafted syslog input
- Denial of service via malformed events
Out of scope:
- Vulnerabilities in third-party dependencies (report to the upstream project)
- Issues requiring physical access to the machine running Qute
- Issues only reproducible with malicious local access