At LearnSphere, the safety of our students, teachers, and their educational data is incredibly important to us. As an AI-powered educational platform, we are committed to maintaining a secure environment.
We recommend all users and contributors stay on the latest version of the repository. Security updates are actively maintained on the main branch.
| Version / Branch | Supported |
|---|---|
main |
✅ |
If you discover a security vulnerability—especially concerning XSS vulnerabilities, Google Gemini API Key exposure, or localStorage data manipulation—we deeply appreciate your help in disclosing it to us responsibly.
Please DO NOT report security vulnerabilities via public GitHub issues.
Instead, please report them privately to ensure the safety of our users while we work on a fix:
- GitHub Security Advisory: Navigate to the "Security" tab of this repository and click "Report a vulnerability" to open a private advisory directly with the maintainers.
- Direct Contact: If you have the maintainer's direct contact information (@omroy07), please reach out privately.
- A descriptive title for the vulnerability.
- A detailed description of the vulnerability (e.g., bypassing AI Tutor safety filters, XSS on progress dashboard).
- Steps to reproduce the issue (code snippets, logs, or screenshots).
- Any potential mitigation or fix if you have one in mind.
- Acknowledgement: We will acknowledge receipt of your vulnerability report within 48 hours.
- Assessment: We aim to triage and provide a preliminary assessment within 7 days.
- Action: If a patch is required, we will prioritize it immediately to protect the LearnSphere community.
Thank you for helping us make LearnSphere a safe, secure, and reliable educational platform! 📚