Reporting a vulnerability¶
If you have found a security problem in one of our extensions, in this documentation, or in the sites that serve it, write to security@kyvero.dev.
That address is the support inbox under a second name, not a second team. The same people read it, and it exists so that a report is not queued behind a question about a date format. You do not need a customer number, an account or a licence to use it. If you found the problem in a copy you never bought, this page is written for you.
Include enough that we can reproduce it: which extension and which version, which OpenCart and PHP version, the steps or the request, and what somebody gets out of it. The support page lists the rest of what turns a first reply into an answer. Do not send credentials, neither yours nor anybody else's.
What happens, and when¶
- Acknowledged within one business day, Monday to Friday, Europe/Amsterdam. That is not a second promise: it is the support window reached through a second address.
- Assessed within five business days. By then you have our reading of it: whether we reproduced it, whether we agree it is a security problem, and what we think it is worth.
There is no fix window, and that is a decision rather than a gap. How long a fix takes depends on what broke, and a date published in advance of knowing that would be a number we had no way to keep. The two windows above are about our attention, which is the part we control; a delivery date is not. What you get instead is the state of it: what we are doing, when we expect to ship, and another word from us when either changes. A fix arrives as a patch release, and the extension's changelog says what it was.
What we ask of you¶
Please give us ninety days before you publish. That is a request, and it is not a condition of anything else on this page. We ask because you are about to describe a way into stores that have no fix available yet, and because the fix is ours to ship rather than theirs. That asymmetry is the reason for asking.
Nothing here is withdrawn if you say no. If the ninety days runs out and there is still no fix, publish. If what you found is already being exploited, tell us and publish on whatever timetable that calls for.
What we promise you¶
Safe harbour. If you are acting in good faith within the scope below, we will not pursue you and we will not ask anyone else to, on two counts named separately because they are two different permissions:
- For testing. Against your own installation, or against the demo store at https://demo.kyvero.dev/.
- For quoting our source. In your report, in an advisory, or in a writeup. The licence carries a named exception for exactly this, granted to anyone acting in good faith through any channel, whether or not they are a customer, and not conditional on the ninety days we asked for above.
Good faith means the ordinary things: your own data, nobody else's store, no denial of service, no social engineering of us or of a customer, no holding a finding back for payment, and stopping once you have proved the point instead of seeing how much further it goes.
What is in scope¶
Three tiers, and the first is the one worth reading twice.
- Our code, and our claims about it. Anything under
extension/<code>/in a package we ship, plus these documentation pages and the sites that serve them. This includes our own security verdict pages: a verdict page that overstates what we check, or what we found, is itself a reportable security problem, because a buyer reads it as an assurance. Omission counts: a result the page should carry and does not is an overstatement made by subtraction. - OpenCart core, and other people's extensions: forwarded, not fixed. If what you found is in OpenCart itself or in somebody else's code, send it anyway. We will pass it to whoever owns it and tell you that we have. We will not fix it and we will not write about it, because it is not ours to disclose.
- The demo store: our code yes, its configuration no. The demo runs our extensions, so our code found running there is in scope like any other copy of it. The store around it is not: a throwaway shop's passwords, its mail setup, its permissions and the hardening it has not had are properties of being a demo, not findings.
No bounty¶
We do not pay for reports. Saying so here is fairer than letting you find out after the work. There is no programme, no tiers and nothing to claim.
What there is, is credit. If you want to be named on this page, say so in your report and tell us how you want it written. If you would rather not be, that is what happens by default, and you do not have to give a reason.