If you discover a security vulnerability, please do not open a public issue.
Instead, email torshid@gmail.com with details. Include:
- A description of the vulnerability
- Steps to reproduce
- The affected module(s) and version(s)
- Any potential impact
You will receive a response within 24 hours. We will work with you to understand the issue and coordinate a fix and release timeline.
| Version | Supported |
|---|---|
| 4.x.x | ✅ |
| 3.x.x | ❌ |
| 2.x.x | ❌ |
Security issues in the following areas are in scope:
- Filter expression injection that bypasses access controls
- Field name manipulation that exposes restricted fields
- Parsing vulnerabilities (stack overflow, OOM)
- Type conversion exploits
- Any mechanism that allows unauthorized data access through filter expressions
We follow a coordinated disclosure process:
- The reporter submits the vulnerability privately.
- We acknowledge receipt within 24 hours.
- We investigate and develop a fix.
- A patch release is prepared.
- The vulnerability is disclosed publicly after the fix is released.
- Credit is given to the reporter in the release notes (unless anonymity is requested).