Before reporting a dubious security "vulnerability", please keep in mind what Nikola is:
- Nikola is a command-line app, executed locally by the user.
- Users of Nikola are mostly software engineers. Showing detailed technical errors is the expected behaviour.
- Input is generally trusted, produced by the user.
- The servers (
nikola autoandnikola serve) are expected to be used in trusted local networks. They are not supposed to be exposed to the public Internet.
Given our threat model, there is no private vulnerability reporting channel. If you find an actual security issue, please report it via GitHub Issues.
There are no bug bounties or other forms of compensation for vulnerability reports.
If you use an LLM ("AI") to find a "vulnerability", it will be closed without response, and your GitHub account will be blocked from the project without warning.
(We have seen slop security reports produced by LLMs, and they were complete nonsense.)