Security: RoboSats/robosats
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Coordinator notice message is rendered as raw HTML, so a coordinator can run JavaScript in the appGHSA-p353-f8m7-8v95 published
Aug 20, 2026 by KoalaSatModerate -
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in RoboSats/robosatsGHSA-vp6p-w2r2-jj2v published
Aug 20, 2026 by KoalaSatModerate -
Password-protected (private) orders can be viewed by anyone through the APIGHSA-r6f6-x59j-8q69 published
Aug 20, 2026 by KoalaSatModerate -
pull_request_target workflow checks out PR head — RCE via malicious PR (py-linter.yml)GHSA-rxx8-rv5g-wpch published
Aug 20, 2026 by KoalaSatHigh -
CI workflow injection via pull_request_target + npm postinstall in js-linter.ymlGHSA-xjwx-6j4q-hrr6 published
Aug 20, 2026 by KoalaSatHigh
Learn more about advisories related to RoboSats/robosats in the GitHub Advisory Database