MedInternia is a healthcare-focused learning and collaboration platform, so security reports should be handled carefully and privately.
Security fixes are currently accepted for the main branch.
Please do not open a public issue for sensitive vulnerabilities.
To report a security concern:
- Contact the maintainers listed in
README.md. - Include the affected area, reproduction steps, expected impact, and any safe proof of concept.
- Avoid sharing real patient, student, or private medical data in reports.
Maintainers should acknowledge valid reports as soon as possible and coordinate a fix before public disclosure.
Examples of security issues include:
- Authentication or authorization bypass
- Exposure of private user or medical data
- Injection vulnerabilities
- Unsafe file upload behavior
- Leaked secrets or insecure default configuration