Please report security vulnerabilities through GitHub Private Advisories. Do not open a public issue.
We will acknowledge your report within 72 hours and aim to release a fix within 60 days. If we need more time we will let you know. We will credit you in the advisory and changelog when the fix is published.
In scope:
- Vulnerabilities in this codebase that would affect any self-hosted Wanderer instance
Out of scope:
wanderer.toand any other publicly hosted instances — do not test against servers you do not own or operate- Vulnerabilities in third-party dependencies — please report those upstream
- Theoretical issues without a working proof of concept
Only the latest release receives security fixes. We do not backport patches to older versions.