Security
Responsible Disclosure
We take the security of our systems and our clients' data seriously. If you've discovered a vulnerability, we want to hear from you — and we'll work with you to resolve it quickly.
Report a vulnerability
Transparency
Disclosed Vulnerabilities
We publicly disclose resolved vulnerabilities to promote transparency and help the wider security community.
- Medium
Reflected XSS in contact form error message
Unsanitised query parameter was reflected in a validation error message, allowing script injection via a crafted URL.
Website (galaxen.co)
12 Apr 2026
Fixed - Low
Open redirect on post-authentication callback
The redirect_to parameter after login was not validated against an allowlist, enabling phishing via a redirect to an external domain.
Client Portal
28 Apr 2026
Fixed - High
API rate-limiting bypass via header spoofing
Forwarding the X-Forwarded-For header to a loopback address circumvented per-IP rate limits on the public API.
API
3 Jun 2026
Investigating
Prefer to email?
Send encrypted reports directly to our security team.