Repository navigation
Security
github-actions[bot] edited this page Jul 2, 2026
·
1 revision
We take security seriously. If you discover a security vulnerability in Inbix, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, please email: security@inbix.xyz
Include the following:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
| Action | Timeline |
|---|---|
| Acknowledge receipt | Within 48h |
| Initial assessment | Within 7 days |
| Fix or mitigation | Within 30 days |
| Public disclosure | After fix is released |
Inbix implements the following security measures:
All HTML email content is sanitized before rendering. The sanitizer:
- Allows only a safe subset of HTML tags
- Strips
script,style,iframe,object,embedtags - Removes event handler attributes (
onclick,onload, etc.) - Blocks dangerous CSS (
expression(),javascript:,position: fixed/absolute) - Validates URL protocols (only
http,https,mailto,cid,data:image) - HTML is rendered in a sandboxed iframe with strict CSP
- Maximum attachment size: 10MB
- Blocked content types (executables, batch files)
- Maximum 20 attachments per message
- Attachments stored in R2, served with
Content-Disposition: attachment
- 60 requests per minute per IP (configurable)
- 10 inbox creations per minute per IP
- Tracked via Cloudflare KV with automatic expiration
-
Content-Security-Policy— restrictive CSP on all responses X-Content-Type-Options: nosniffX-Frame-Options: DENYReferrer-Policy: strict-origin-when-cross-origin-
Permissions-Policy— camera, microphone, geolocation disabled
- Only configured origins are allowed
- Credentials are not sent cross-origin
- All database queries use Drizzle ORM with parameterized queries
- No raw SQL string concatenation
- API keys are hashed with SHA-256 before storage
- Keys are never logged or returned in API responses
- Constant-time comparison for key validation
When self-hosting Inbix, ensure:
-
CORS_ORIGINis set to your specific domain (not*) - Email Routing is configured with a catch-all to the Worker
- D1 database is not publicly accessible
- R2 bucket has no public access (all access via Worker)
- Rate limiting KV namespace is active
-
wrangler.tomldoes not contain secrets (usewrangler secret put) - HTTPS is enforced (Cloudflare does this by default)
- Dependencies are kept up to date
-
pnpm auditis run in CI - No
eval()ornew Function()in the codebase - No
dangerouslySetInnerHTMLin React (HTML rendered via sandboxed iframe)
This policy applies to the main inbix repository. Third-party integrations and custom deployments are out of scope.
We thank all security researchers who responsibly disclose vulnerabilities.