Skip to content

Security: Uncodedtech/photoprism

Security

SECURITY.md

PhotoPrism® Security Policy

Please contact us at security@photoprism.app when you have discovered a potential security issue. You are welcome to also report vulnerabilities in third-party applications that we may not be able to fix directly.

At a minimum, your report should include the following:

  • version and architecture
  • vulnerability description
  • reproduction steps
  • confirmation that you have reproduced the behavior yourself on a running instance

When we receive a meaningful and verifiable vulnerability report from you, we will try to reproduce the issue, determine the impact and get back to you as soon as possible.

We kindly ask you not to send HTML emails for this purpose, but only plain text. Confirmed vulnerabilities will be fixed within 90 days, depending on the severity and whether third-party packages are affected.

This Security Policy was last updated on August 13, 2026.

Responsible Disclosure

  1. Confirm that the vulnerability applies to a current version and is reproducible.
  2. First share the vulnerability details with us so that users are not put at risk.
  3. Allow us 90 days before publishing details, so that everyone has had a chance to update.
  4. Let us know before you request a CVE ID, and respect the privacy of others.

Avoid activities that disrupt, degrade, or interrupt our services or compromise other users' data, such as spam, brute force attacks, denial of service attacks, and malicious file distribution.

Publication and CVE Identifiers

We ask for 90 days between your report and any public disclosure, including a request for a CVE ID. That is the same period within which we commit to fixing confirmed vulnerabilities. If a fix is available sooner, we will tell you, and you are welcome to publish once users are able to update. If we need longer, we will say so and explain why.

If you intend to request a CVE ID, please tell us first. Contact us before you approach a CVE Numbering Authority (CNA), and if an identifier has already been requested or assigned, please include it together with the name of the assigning CNA in your first message to us. Under the CVE Program's CNA Operational Rules, a CNA is expected to make a good faith effort to notify the vendor before a record is published. Our contact details are published in security.txt and in the SECURITY.md file of our public repository, so there is always a documented way to reach us.

When a record is published without an attempt to contact us, we ask the assigning CNA to correct or reject it. We also raise the matter with the CNA's Root if the rules were not followed and publish our own assessment alongside the record. However, we would much rather agree on an accurate advisory with you before publication.

Bug Bounty Program

We do not operate a bug bounty program and do not offer payment or comparable compensation for vulnerability reports. We are a small team, and the time we can spend on inbound reports is the same time we spend on fixing issues and building the product.

Reporting Issues as a Business or Organization

(a) If an email we receive appears to be auto-generated — for example unreviewed output from an automated scanner or a language model — and does not look like a legitimate report that has been manually reviewed in accordance with the requirements of this policy, we may ignore it and you should not expect a response in order to protect our ability to respond to actual issues.

(b) Unless absolutely necessary, for example to report a major issue that has just been discovered, please send requests or reports during regular business hours and never at night or on weekends, especially if they are sent asynchronously.

(c) Refrain from sending HTML emails as we consider them insecure and unsuitable for this purpose.

(d) If you are contacting us as a business or organization, we encourage you to include legal and contact information on your website, as failure to provide legally required information may compromise your eligibility and trustworthiness.

There aren't any published security advisories