Please report security issues to security@karakeep.app
Security: karakeep-app/karakeep
Security
SECURITY.md
-
Reddit plugin content bypasses DOMPurify sanitization, enabling stored XSSGHSA-mg93-f9mw-wpgj published
Feb 22, 2026 by MohamedBassemHigh -
Current authentication flow is vulnerable to time based user enumerationGHSA-g49h-4fx9-9wmw published
Aug 23, 2025 by MohamedBassemLow -
Cross-Site Scripting within assets functionalityGHSA-7cj2-fr83-g2wj published
Aug 23, 2025 by MohamedBassemHigh
Learn more about advisories related to karakeep-app/karakeep in the GitHub Advisory Database