| Version | Supported |
|---|---|
main |
Yes |
Do not open a public GitHub issue for security problems.
Use GitHub private vulnerability reporting if available, or contact the repository owner with:
- Description of the issue and impact
- Steps to reproduce
- Affected version / commit
You should receive a response within a reasonable timeframe. We will coordinate disclosure and credit if you want it.
In scope: authentication bypass, authorization flaws, remote code execution via the panel, Docker escape via panel-controlled options, secret leakage through API responses.
Out of scope: denial of service against your own panel without a specific bug, misconfiguration of Docker socket permissions on the host, brute force when login rate limits are disabled by running a modified build.