Please do not open a public GitHub issue for security vulnerabilities. To report a vulnerability, use GitHub's private vulnerability reporting feature for this repository, or email us at security@karakeep.app.
Security: karakeep-app/karakeep
Security
SECURITY.md
-
SSRF Protection Bypass via Redirect Handling in KarakeepGHSA-g647-327m-79g9 published
May 8, 2026 by MohamedBassemHigh -
SSRF via metascraper-logo-favicon bypasses validateUrl protectionsGHSA-7rx4-c5vx-g8w3 published
May 8, 2026 by MohamedBassemHigh -
Reddit plugin content bypasses DOMPurify sanitization, enabling stored XSSGHSA-mg93-f9mw-wpgj published
Feb 22, 2026 by MohamedBassemHigh -
Current authentication flow is vulnerable to time based user enumerationGHSA-g49h-4fx9-9wmw published
Aug 23, 2025 by MohamedBassemLow -
Cross-Site Scripting within assets functionalityGHSA-7cj2-fr83-g2wj published
Aug 23, 2025 by MohamedBassemHigh
Learn more about advisories related to karakeep-app/karakeep in the GitHub Advisory Database