Automation Control exposes operator views and control workflows. Use coordinated disclosure; never report vulnerability details, credentials, certificates or real plant data in a public issue.
| Version | Support |
|---|---|
0.0.1 |
Current integration/pilot release; best effort |
Use Security → Report a vulnerability in this repository. Include the version/commit, safe lab reproduction, attacker prerequisites, impact, sanitized evidence and mitigation if known. If private reporting is unavailable, contact the Centaurus-X maintainer and agree on a private channel.
Priority areas include authentication or Origin bypass, read-only fencing bypass, command substitution/correlation confusion, unsafe SVG content, snapshot path traversal, secret disclosure, WebSocket queue exhaustion and Proxy session/CSRF/TLS boundary failures.
- Use production PKI; do not ship generated lab keys.
- Set access/read-only tokens and a strict Origin allowlist.
- Keep upstream credentials outside the repository and logs.
- Terminate remote access through authenticated TLS and least-privilege network policy.
- Qualify every operator action against an isolated simulator before real equipment.
- Monitor rejected sessions, dropped frames, reconnects and failed operations.
No independent penetration test, safety certification or compliance certification is claimed.