Only the latest commit on main is supported. Please reproduce issues against
main before reporting.
Do not open a public issue for security vulnerabilities.
Report privately via GitHub's private vulnerability reporting
(Security → Report a vulnerability) or by email to justin@jnlte.de.
Please include a description of the issue, steps to reproduce, and the impact you expect. You can expect an initial response within 7 days.
In scope: the reporter service, the container configuration in
docker-compose.yml, the patched Cowrie Dockerfile, and the helper scripts.
Out of scope: vulnerabilities in Cowrie itself (report those upstream) and in the Avatoris API.
A honeypot is an intentionally exposed system. Run it only on infrastructure you own or are authorized to operate, keep it isolated from anything sensitive, and never reuse real credentials or hostnames in its configuration.