Skip to content

Security: Centaurus-X/Automation_Control

SECURITY.md

Security policy

Automation Control exposes operator views and control workflows. Use coordinated disclosure; never report vulnerability details, credentials, certificates or real plant data in a public issue.

Supported version

Version Support
0.0.1 Current integration/pilot release; best effort

Report a vulnerability

Use Security → Report a vulnerability in this repository. Include the version/commit, safe lab reproduction, attacker prerequisites, impact, sanitized evidence and mitigation if known. If private reporting is unavailable, contact the Centaurus-X maintainer and agree on a private channel.

Priority areas include authentication or Origin bypass, read-only fencing bypass, command substitution/correlation confusion, unsafe SVG content, snapshot path traversal, secret disclosure, WebSocket queue exhaustion and Proxy session/CSRF/TLS boundary failures.

Deployment baseline

  • Use production PKI; do not ship generated lab keys.
  • Set access/read-only tokens and a strict Origin allowlist.
  • Keep upstream credentials outside the repository and logs.
  • Terminate remote access through authenticated TLS and least-privilege network policy.
  • Qualify every operator action against an isolated simulator before real equipment.
  • Monitor rejected sessions, dropped frames, reconnects and failed operations.

No independent penetration test, safety certification or compliance certification is claimed.

There aren't any published security advisories