CVD Policy

Coordinated Vulnerability Disclosure (CVD) Policy

ModuleWorks GmbH (“ModuleWorks”, “we”) takes the security of our software seriously. This policy describes how to report a suspected security vulnerability in a ModuleWorks product to us, what to expect after you report one, and the terms under which we welcome good-faith security research.

This policy applies to all ModuleWorks products with digital elements — including the ModuleWorks SDK, our Python, Node.js, and .NET packages, and our web services — and to the ModuleWorks-owned source code, CI/CD infrastructure, and websites that support them.

Scope

In scope:

  • Any version of a ModuleWorks product that is currently receiving security updates. (see that product’s own documentation for its current support period).
  • ModuleWorks-operated infrastructure directly involved in developing, building, or delivering those products (e.g. our package registries, release infrastructure, and public websites).
  • Vulnerabilities in third-party components we bundle or depend on, where the vulnerability is reachable through a ModuleWorks product — please also consider reporting directly to that component’s own maintainer.

Out of scope:

  • Products or versions that are past their published end of support.
  • Third-party services, products, or websites we do not operate, even if linked from ModuleWorks properties.
  • Findings that require physical access to a device, social engineering of ModuleWorks staff or customers, or denial-of-service testing against production systems.
  • Reports without a working proof of concept, or based solely on automated scanner output without independent verification.

How to Report a Vulnerability

You can report suspected vulnerabilities via our regular support channels as described in our documentation or send a mail to: security@moduleworks.com

Such reports will be reviewed and processed by humans.

To help us triage quickly, please include, as far as you’re able to:

  • The affected product and version (or commit/build identifier).
  • A description of the vulnerability and its potential impact.
  • Step-by-step reproduction instructions or a proof of concept.
  • Whether you believe the vulnerability is being actively exploited.

We will communicate with you via the channel you used for reporting the vulnerability.

What Happens After You Report

Stage
Target
Acknowledgment of receipt
Within 2 business days
Initial triage and severity assessment
Within 5 business days of acknowledgment
Coordinated public disclosure
Once a fix is available, or no later than 90 days after our acknowledgment,
whichever comes first

Remediation timelines depend on severity and complexity and cannot be promised as a fixed number of days; we will keep you informed of progress throughout. Once a fix is available, we publish a description of the vulnerability, the affected product(s) and version(s), its severity, and remediation guidance (e.g. as part of that product’s release notes or CVE/vulnerability report), and disseminate the security update itself free of charge and without undue delay.

If your report indicates a vulnerability that is already being actively exploited, or an incident that could affect the security of a ModuleWorks product, we treat it with immediate priority: our internal response is separately bound by regulatory notification deadlines (EU Cyber Resilience Act Article 14) that are considerably faster than the general timeline above.

Coordinated Disclosure and Safe Harbor

We ask that you:

  • Give us a reasonable opportunity to investigate and remediate an issue before disclosing it publicly, per the coordinated-disclosure timeline above.
  • Avoid privacy violations, service disruption, and destruction of data while investigating a suspected vulnerability.
  • Only interact with accounts, data, or systems you own or have explicit permission to test.

If you make a good-faith effort to comply with this policy while researching or reporting a vulnerability, ModuleWorks will not pursue legal action against you for that research, and we will work with you to understand and resolve the issue quickly.

Contact and Updates

Questions about this policy, outside of an active vulnerability report, can be sent to the same address above. This policy is reviewed periodically and may be updated; the version in effect at the time of your report governs how that report is handled.

Contact