| Version | Security Fixes |
|---|---|
| 0.1.x | ✅ Yes |
Please do not open a public GitHub issue for security vulnerabilities.
Please report security vulnerabilities by creating a private advisory in the GitHub Security tab of this repository. Include:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested mitigation
In scope:
- Arbitrary code execution via malformed invoice input
- Information disclosure via error messages
- XML External Entity (XXE) injection in generated XML
- Denial of service via crafted inputs
Out of scope:
- Issues in
@e-invoice-eu/coreor other upstream dependencies (report to them directly) - Issues requiring physical access to the host machine