Skip to content

Security: c9dev/penguin-mail

SECURITY.md

Security

Penguin Mail holds OAuth tokens for Gmail accounts and renders mail from strangers, so a flaw can expose someone's mail.

Report a vulnerability privately through GitHub's security advisories, not in a public issue. Include the version, the steps that show the problem, and what an attacker gains.

Only the latest release gets fixes.

There aren't any published security advisories