| Version | Supported |
|---|---|
Latest main |
Yes |
| Older commits | No |
Please do NOT open a public issue for security vulnerabilities.
Email mailwangjk@gmail.com with:
- Description of the vulnerability
- Steps to reproduce
- Impact assessment (if known)
- Acknowledgement: within 72 hours
- Status update: within 7 days
- Fix or mitigation: as soon as reasonably possible
- SQL injection or query manipulation
- Path traversal (file read/write outside intended directories)
- Shell command injection via
shell_execor similar - Unintended data exposure (profile data, credentials, API keys)
- Authentication or authorization bypass
- Vulnerabilities in third-party dependencies (report upstream)
- Denial of service attacks
- Physical access attacks
- Social engineering
We follow coordinated disclosure. We will credit reporters in the changelog unless anonymity is requested.