Security reports are assessed, prioritized by severity, and handled through the private reporting process below.
Please do not open public issues for security vulnerabilities.
Use one of the following private channels:
- GitHub Security Advisory:
Securitytab in this repository - HauntedMC support: https://www.hauntedmc.nl/support
Include:
- Affected deployment details
- Reproduction steps / proof of concept
- Impact assessment
- Any proposed mitigation
- We acknowledge reports as quickly as practical.
- We validate impact, prioritize by severity, and prepare a fix.
- We coordinate disclosure after a fix or mitigation is available.
Please allow maintainers time to validate and patch before public disclosure.