Security

DayPilot takes security issues seriously. This page provides information about reporting security vulnerabilities and lists published security advisories affecting DayPilot products.

Report a Vulnerability

If you believe you have found a security vulnerability in DayPilot, please report it privately so we can investigate and coordinate a fix before public disclosure.

Please include, where possible:

  • the affected DayPilot product and version,

  • a description of the issue and its security impact,

  • steps to reproduce the behavior,

  • a minimal proof of concept,

  • any known prerequisites for exploitation.

Please do not disclose the vulnerability publicly before we have had an opportunity to investigate and prepare a fix.

Contact: support@daypilot.org

We will acknowledge valid reports, investigate the issue, and coordinate disclosure with the reporter where appropriate.

Security Advisories

Published DayPilot security advisories are listed below.

2026-08-21: Prototype Pollution in DayPilot Configuration Option Processing

A prototype-pollution vulnerability affecting DayPilot Lite and DayPilot Pro configuration processing.

The issue is only exploitable when an application passes untrusted JSON, or an object preserving attacker-controlled top-level property names, as DayPilot component configuration. Ordinary untrusted event or resource data does not by itself expose the vulnerability.

Severity: Low
Fixed versions: See the advisory for product-specific version information.

View security advisory

Security Updates

Security fixes are included in regular DayPilot releases unless otherwise stated in the corresponding advisory.

Users should upgrade to the fixed version listed in the relevant advisory. Where immediate upgrading is not possible, an advisory may also provide a temporary workaround.

Scope

Security advisories may apply to one or more DayPilot products, including DayPilot Lite and DayPilot Pro distributions for JavaScript and supported frameworks.

An advisory identifies the affected products and version ranges individually. Framework-specific packages may be listed as affected when they include or export vulnerable DayPilot core classes, even if the native framework wrapper itself does not directly exercise the vulnerable code path.