We release patches for security vulnerabilities. The following versions are currently supported:
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
The React Image Editor team and community take security bugs seriously. We appreciate your efforts to responsibly disclose your findings, and will make every effort to acknowledge your contributions.
Please do not report security vulnerabilities through public GitHub issues.
Instead, please report them via email to: yuis.ice@example.com
You should receive a response within 48 hours. If for some reason you do not, please follow up via email to ensure we received your original message.
Please include the following information in your report:
- Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)
- Full paths of source file(s) related to the manifestation of the issue
- The location of the affected source code (tag/branch/commit or direct URL)
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue, including how an attacker might exploit the issue
This information will help us triage your report more quickly.
We prefer all communications to be in English.
React Image Editor processes images entirely on the client-side using the Canvas API. This means:
✅ Secure by Design:
- No images are uploaded to external servers
- All processing happens in the user's browser
- No data leaves the user's device without explicit action
- Large images may cause browser memory issues
- Malformed image files could potentially crash the browser
- Cross-origin images may have CORS restrictions
We regularly monitor our dependencies for security vulnerabilities:
- React: Core framework - security patches applied promptly
- TypeScript: Compile-time type safety
- Zustand: Minimal state management library
- Vite: Build tool with security best practices
The application relies on modern browser security features:
- Canvas API: Native browser implementation
- File API: Secure file reading with user consent
- Same-Origin Policy: Prevents unauthorized resource access
- Only open image files from trusted sources
- Be cautious with very large image files (>50MB)
- Regularly update your browser for latest security patches
- Images are processed locally - no data sent to servers
- Clear browser cache if working with sensitive images
- Use private/incognito browsing for confidential work
- File type validation (JPEG, PNG, WebP, GIF)
- File size limits to prevent memory exhaustion
- Canvas bounds checking to prevent buffer overflows
- Graceful degradation for unsupported features
- Safe error messages that don't leak system information
- Proper cleanup of canvas contexts and image data
- Automatic cleanup of unused image data
- Limits on undo/redo history to prevent memory leaks
- Efficient canvas reuse patterns
- Large File Processing: Very large images (>100MB) may cause browser instability
- Memory Usage: Extended editing sessions may consume significant RAM
- Browser Compatibility: Older browsers may have reduced security features
Security updates will be released as soon as possible after discovery. Users will be notified through:
- GitHub Security Advisories
- Release notes with security tags
- README updates for critical issues
- Day 0: Security issue reported via email
- Day 1-2: Initial response and acknowledgment
- Day 3-7: Issue verification and assessment
- Day 8-30: Patch development and testing
- Day 31: Public disclosure and patch release
We will work with you to ensure proper attribution for your discovery.
We recognize security researchers who help improve our project:
No security issues have been reported yet.
For any security-related questions or concerns, please contact:
- Security Email: yuis.ice@example.com
- Project Maintainer: @yuis-ice
- GitHub Security: Security Advisories
Thank you for helping keep React Image Editor and our users safe! 🔒