| Version | Supported |
|---|---|
| Latest release | ✅ |
| Older releases | ❌ |
If you discover a security vulnerability in HyperPack, please report it responsibly:
- Do not open a public issue
- Email the maintainer directly (see GitHub profile)
- Include a description of the vulnerability and steps to reproduce
- Allow reasonable time for a fix before public disclosure
HyperPack processes untrusted input files (compressed archives). Security-relevant areas include:
- Buffer overflows in decompression routines
- Integer overflows in size calculations
- Malformed HPK files causing crashes or infinite loops
- Memory exhaustion via crafted inputs
The web app runs entirely client-side via WebAssembly. No files are uploaded to any server. The WASM sandbox provides an additional layer of isolation.