Reporting a security problem
QKVM holds the passwords of your KVMs and can press the power button of the machines behind them, so problems in it matter. Reports are welcome.
Reporting a problem
Please do not open a public issue for something that could be used against other people's installations. Report it privately instead: on https://github.com/qkvm/qkvm open the Security tab and choose Report a vulnerability.
Say which version you run (python -m qkvm --version, or Settings → About), what you did, and what happened. A way to reproduce it helps most.
What counts
- Getting past sign-in, a role, or the limit of an account to some KVMs.
- Reading a stored password, the recovery key, a two-factor key or the alert address, from the page, the log, or the data folder without an account's password.
- Making QKVM send a KVM's password to something other than that KVM.
- Running code on the computer QKVM runs on, including through the updater.
- A page on another website making a signed-in browser do something in QKVM.
What QKVM assumes
- Whoever can read the memory or the files of the computer it runs on while it is unlocked is trusted. The data folder alone, without an account's password, should give nothing away.
- The network between QKVM and a KVM may be hostile; that is why certificates are remembered. The network between a browser and QKVM should be trusted, or HTTPS switched on.
- An admin is trusted with everything, including where alerts are sent.
How the protections work is described in the README under How it is protected.