Node.js (no recompile required):
- H-04: RUSTDESK_API_DISABLE_TOTP now requires explicit _ACKNOWLEDGED flag
- M-03: drop Referer-based skip from apiLimiter; add dedicated widgetLimiter
- M-06: gate /api/system/info, /logs/recent, /database/stats, /docker/containers, /speed-test behind requirePermission('metrics.view')
- L-01: startup banner now warns when TRUST_PROXY is off in production / errors when TOTP bypass is set without acknowledgement
Scripts / Docker:
- M-04: betterdesk.sh migration tool invocation switched from eval(cmd-string) to bash array exec
- M-05: all admin / PostgreSQL password generators switched from openssl rand -base64+tr+head to openssl rand -hex 16 (full entropy)
- L-02: docker-compose.yml / single.yml / quick.yml services gain security_opt: no-new-privileges and cap_drop: ALL
Documentation:
- I-04: add SECURITY.md (supported versions, reporting channels, SLA, scope, hardening defaults)
Go server (requires rebuild on host: cd betterdesk-server && go build ./...):
- H-03: /metrics now gated by METRICS_IP_ALLOWLIST / METRICS_PUBLIC; per-username login + 2FA rate-limit added on top of per-IP
- M-07: enrollment (/api/devices/register*) and branding (GET /api/branding) endpoints rate-limited per IP
- I-02: bd-mgmt WebSocket gets SetReadLimit(16 MiB) to bound memory
- L-04: auth middleware skips noisy public probes and redacts /peers/{id} segments
This commit was made possible thanks to Insolve.
4.1 KiB
Security Policy
This document describes how to report security vulnerabilities in BetterDesk and what to expect from the maintainers in return.
Supported Versions
Only the latest minor release on the main branch receives active security
patches. Older tagged releases may receive backports for critical issues at the
maintainers' discretion.
| Version | Supported |
|---|---|
main |
✅ |
| latest tag | ✅ |
| older tags | ❌ (best-effort) |
Reporting a Vulnerability
Please do NOT open a public GitHub issue for security problems.
Preferred channels (in order):
- GitHub Security Advisory (private): https://github.com/UNITRONIX/Rustdesk-FreeConsole/security/advisories/new
- Encrypted email:
security@betterdesk.invalid(replace with your real address before publishing; PGP key TBD)
Please include, where possible:
- A clear description of the issue and its impact.
- A reproduction recipe (PoC, request/response, or test case).
- Affected versions / commits / deployment shape (Docker single-container, multi-container, bare-metal install, etc.).
- Any logs, screenshots or traffic captures \u2014 with sensitive data redacted.
Response Targets
- Acknowledgement: within 7 days of report.
- Triage decision: within 14 days (severity, scope, fix plan).
- Coordinated disclosure window: 90 days maximum from acknowledgement, shortened if the issue is being actively exploited.
- Credit: at your option, in the release notes / advisory.
If you do not get an acknowledgement within 7 days, please ping the repository maintainers via a public but vague issue ("waiting on security report acknowledgement"). Do not disclose any details.
Scope
In scope:
- The Go server (
betterdesk-server/) including signal, relay, HTTP/WS API, CDAP gateway, BD-MGMT WebSocket, and the database adapters. - The Node.js web console (
web-nodejs/) including the RustDesk-compatible client API on port21121, the panel routes, and the WS push services. - The Tauri MGMT and Agent clients (
betterdesk-mgmt/,betterdesk-agent-client/). - The native Go agent (
betterdesk-agent/). - The CDAP SDKs and reference bridges (
sdks/,bridges/). - The ALL-IN-ONE install scripts (
betterdesk.sh,betterdesk.ps1,betterdesk-docker.sh) and the Docker compose files.
Out of scope:
- Vulnerabilities that require an attacker who already controls the host operating system, the database file, or the operator's browser session.
- Findings that only apply to legacy Rust binaries in
archive/or to forks. - Denial-of-service from raw network flooding without an amplification vector.
- Self-XSS, missing security headers on documentation pages, or theoretical issues without a concrete exploitation path.
- Reports generated solely by automated scanners without manual validation.
Hardening Defaults
BetterDesk ships with the following defaults that reduce the blast radius of typical issues. Operators should keep them enabled unless they have a specific reason to relax them:
- TOTP-based 2FA enforced on the web panel for all roles.
- WebSocket origin allowlist for the API events endpoint (
API_WS_ALLOWED_ORIGINS). trust proxydisabled by default; must be opted in explicitly when behind a reverse proxy.- Local-only bind for the panel HTTP port (
HOST=127.0.0.1); only the RustDesk client API (21121) is intended for WAN exposure. - Docker containers run with
no-new-privileges:trueandcap_drop: [ALL]. - Admin password and PostgreSQL password generated with
openssl rand -hex 16. - TOTP bypass on the RustDesk client API requires both
RUSTDESK_API_DISABLE_TOTP=trueandRUSTDESK_API_DISABLE_TOTP_ACKNOWLEDGED=true, with a startup banner warning.
Audits
Recent internal audits are published under docs/security/ (e.g.
AUDIT_PRODUCTION_2026-04-10.md). Fixes are referenced in commit messages and
in .github/copilot-instructions.md under the relevant Phase.
This policy was last updated on 2026-04-10.