generated: '2026-08-27' method: searched source: https://github.com/TandoorRecipes/recipes/blob/develop/SECURITY.md summary: >- Tandoor publishes a security policy in SECURITY.md and runs coordinated disclosure through GitHub Security Advisories on the TandoorRecipes/recipes repository. The programme is demonstrably live: 10 CVE-bearing advisories were published between April and June 2026, each cross-referenced from the release notes of the version that fixed it. There is no /.well-known/security.txt, no bug bounty and no separate disclosure page — GitHub Security Advisories is the whole channel. policy: url: https://github.com/TandoorRecipes/recipes/security/policy file: https://github.com/TandoorRecipes/recipes/blob/develop/SECURITY.md http_status: 200 channel: GitHub Security Advisories intake_url: https://github.com/TandoorRecipes/recipes/security/advisories/new supported_versions: >- Latest version only. The policy states plainly that the software is considered beta/WIP and that there are no backports of security or any other fixes to older releases. safe_harbor_stated: false bug_bounty: false security_txt: false security_txt_probe: - url: https://tandoor.dev/.well-known/security.txt status: 404 - url: https://docs.tandoor.dev/.well-known/security.txt status: 404 - url: https://app.tandoor.dev/.well-known/security.txt status: 302 advisories: source: https://github.com/TandoorRecipes/recipes/security/advisories observed: 10 window: 2026-04-03 .. 2026-06-30 recent: - id: GHSA-wjf3-fq5w-7j7w severity: high published: '2026-06-30' summary: Private recipe authorization bypass via /api/step/ — read and modify another space's steps fixed_in: 2.6.12 - id: GHSA-cqj3-64qw-4w52 severity: high published: '2026-06-21' summary: Private recipe file and share-link authorization bypass in recipe utility API endpoints fixed_in: 2.6.10 - id: GHSA-wq4h-2r8x-cv65 severity: high published: '2026-06-21' summary: Blind SSRF via AI provider URL (api_base) fixed_in: 2.6.10 - id: GHSA-f2gw-c2c7-59v7 severity: high published: '2026-06-21' summary: ReDoS via user-controlled automation regex fixed_in: 2.6.10 - id: GHSA-4x57-2q4q-xwpp severity: medium published: '2026-06-21' summary: ORM ORDER BY injection via FK traversal fixed_in: 2.6.10 - id: GHSA-4vw7-c646-g23w severity: medium published: '2026-06-21' summary: Cross-user IDOR in /api/recipe-from-source/ bookmarklet import fixed_in: 2.6.10 - id: GHSA-89pw-5qxc-7v86 severity: medium published: '2026-04-16' summary: Stored XSS via Jinja2 template rendering in recipe instructions fixed_in: 2.6.9 - id: GHSA-xvmf-cfrq-4j8f severity: high published: '2026-04-03' summary: BFLA — CustomIsShared permits DELETE/PUT on RecipeBook by read-only shared users - id: GHSA-8w8h-3pv2-3554 severity: high published: '2026-04-03' summary: Input validation — amount/unit bypass serializer in food/{id}/shopping/ - id: GHSA-9hhh-g2fc-r8x2 severity: medium published: '2026-04-03' summary: Stored CSS injection via