Security updates target the latest published release. Older pre-release versions may receive upgrade guidance instead of a backport.
Use the repository’s Security → Report a vulnerability private reporting function.
Do not open a public issue, discussion, or pull request for:
- authentication or authorization bypasses;
- command injection, path traversal, or unsafe file handling;
- credentials exposed through logs, diagnostics, email, or WebGUI responses;
- backup corruption, manifest forgery, or restore-integrity failures;
- Recovery Testing isolation failures;
- installer, dependency, workflow, or release-chain compromise.
Include the affected plugin and Unraid versions, impact, reproduction steps, and the smallest safe evidence set. Remove real credentials, email addresses, VM data, repository contents, and unrelated diagnostics.
Reports are triaged and coordinated privately. Do not access other users’ data, disrupt systems, or disclose details before a corrective release or agreed disclosure date.
Security research does not grant permission to modify or redistribute the Software beyond rights required by applicable law or separately authorized in writing.