Security fixes are provided for the latest stable WallAI release. Self-hosters should use a numbered image version and review the changelog before updating.
Do not open a public issue for a vulnerability or include secrets, API keys, .env files, or backups in a report.
Use GitHub's private vulnerability reporting feature for this repository. Include the affected version, impact, reproduction steps, and any suggested mitigation. Reports will be acknowledged and assessed before public disclosure.