At Calibre, we believe security and privacy are critically important. To ensure we provide the best possible protection, we ask for responsible disclosure of vulnerabilities in our projects. Thank you for participating and helping us keep Calibre safe!
While at this point, we don’t have a bug bounty program, we will make sure that every report is evaluated and addressed.
If you believe you have found a security vulnerability in this repository, please report it to us through coordinated disclosure.
Instead, please send an email to security[@]calibreapp.com.
Please include as much of the information listed below as you can to help us better understand and resolve the issue:
- The type of issue (e.g., buffer overflow, SQL injection, or cross-site scripting)
- Full paths of source file(s) related to the manifestation of the issue
- The location of the affected source code (tag/branch/commit or direct URL)
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue, including how an attacker might exploit the issue
This information will help us triage your report more quickly.
This policy is based on GitHub’s Security disclosure template.