Security fixes are handled on the latest stable release line only. If you are using an older installer, update to the latest release before reporting a vulnerability unless the issue prevents you from updating.
Do not open a public issue for a suspected security vulnerability. Use GitHub private vulnerability reporting when it is enabled for this repository. If it is not available, contact the maintainer privately before sharing exploit details.
Include:
- the affected version or commit;
- steps to reproduce;
- the impact you believe is possible;
- whether any local files, telemetry databases, or generated map-cache data are involved.
Do not send secrets, personal telemetry databases, local game files, generated map caches, or credentials unless a maintainer specifically asks for a redacted sample.