Skip to content

Security: vtex-apps/admin-pages

SECURITY.md

Security Policy

If you discover a security vulnerability in vtex.admin-pages, please report it privately so it can be triaged and fixed before becoming public.

How to report

  • Email: security@vtex.com
  • Subject: vtex.admin-pages — security
  • Please include: a description of the issue, steps to reproduce, the affected version(s) of the app, and any logs or screenshots that help reproduce.

Disclosure

VTEX follows a coordinated disclosure model. We will acknowledge your report, investigate, and coordinate the fix and disclosure timeline with you.

Out of scope

  • Vulnerabilities in third-party apps consumed by this app — please report those directly to the owning app's security contact.
  • Issues that require credentials, access, or configuration that go beyond the default Admin permissions for this app.

There aren't any published security advisories