Reporting a vulnerability
Open a private security advisory on GitHub or send your report to [email protected]. PGP is available on request. We aim to acknowledge new reports within three business days.
Please don't post reproduction steps or proof-of-concept material in a public GitHub issue, in Discord, on social media, or in community comments before we've coordinated a fix. If you're not sure whether something counts as a security issue, send it anyway and let us decide.
What helps
A useful report usually tells us:
- The version or image digest you tested.
- Steps to reproduce.
- What an attacker can do with it.
- Logs, screenshots, or request samples if you have them.
- Whether you want public credit on the advisory.
We can work with less. Send what you have.
Response targets
After we've acknowledged a report, our targets for shipping a fix are:
| Critical | 7 to 14 days |
| High | 30 days |
| Medium | 60 days |
| Low | 90 days, or rolled into the next release |
These are targets, not contracts. If something slips, we'll tell you why and agree on a new date.
Coordinated disclosure
The default embargo is the fix release plus 30 days before any public detail goes out. If you need a longer or shorter window, say so in your report and we'll work it out.
When a finding touches an upstream project (Proxmox VE, an OIDC library, an npm package), we file the upstream report alongside ours and align the timing so the advisories don't trip over each other.
In scope
- The official Tainer container image (tainersh/tainer).
- Application code, server actions, REST routes, and the mobile API surface.
- Authentication, sessions, 2FA, password reset, and SSO flows.
- Authorization, roles, groups, and per-site permissions.
- How Tainer stores Proxmox credentials, OIDC client secrets, and SMTP credentials.
- Audit log integrity and coverage.
- Container hardening and the supply chain around image builds and Docker Hub publication.
Out of scope
- Bugs in Proxmox VE itself. Report those to the Proxmox project.
- Bugs in the identity provider you connected (Entra, Okta, Auth0, Keycloak, Google Workspace, etc.). Report to the vendor.
- Bugs in the reverse proxy you chose. That's operator-selected software.
- Bugs in npm dependencies, unless Tainer's specific use is what surfaces them.
- Operator misconfiguration the docs warn against (weak admin passwords, exposing port 3000 directly, missing TLS, etc.).
- Volumetric or traffic-flooding denial of service. Rate-limit at your reverse proxy or WAF.
- Self-XSS, missing security headers without realistic impact, and other findings that don't translate to a real-world attack.
- Issues that need physical access to the Tainer host.
- Social engineering of maintainers, contributors, or other operators.
If something is out of scope but interesting, we still want to hear about it. We'll reply with what we can do.
Safe harbor
If you make a good-faith effort to follow this policy, we won't pursue legal action, won't try to identify you beyond what we need to coordinate, and will work with you on disclosure and credit.
In return, we ask that you don't access data that isn't yours, don't run automated scanners against shared community deployments, and don't keep credentials or operator data after testing. If your testing accidentally goes outside this scope, tell us. Honest mistakes get worked out.
Test environments
Reproduce against your own Tainer deployment in a private network. Don't test against tainer.sh or any infrastructure we run on behalf of customers. If a finding needs a particular IdP behaviour to demonstrate, set up a throwaway provider (Keycloak in Docker works) instead of leaning on a third-party service.
Don't include real credentials, customer data, or third-party data in proof-of-concept material.
Supported versions
We patch security issues on the current stable release. Older releases get fixes case by case based on severity and how disruptive the upgrade is. Pin a digest in production, and read the release notes before upgrading.
The current supported branch is shown on Docker Hub and on the changelog.
Hardening guidance
For production deployments:
- Run Tainer behind TLS.
- Restrict access to trusted networks or identity-aware access controls. Don't expose port 3000 directly to the public internet.
- Use a least-privilege Proxmox API token instead of a root credential.
- Pin the image to a digest. The latest tag is mutable.
- Back up the data volume before upgrades.
- Keep the host OS, Docker, Proxmox VE, and Tainer current.
- Use long admin passwords and enable 2FA.
- Read the audit log and container logs regularly.
Contact
Security reports: [email protected]
Anything else: [email protected]