We take security vulnerabilities seriously. If you discover a security issue in QuickStack, please report it privately before disclosing it publicly.
Please do not open a public GitHub issue for security vulnerabilities.
Send your report by email to:
To help us triage and fix the issue quickly, please include:
- A clear description of the vulnerability and its impact.
- The affected component, endpoint, or file (if known).
- Steps to reproduce, including a minimal proof of concept if possible.
- Your environment details (QuickStack version, deployment method, etc.).
- Any suggested fix, if you have one.
- We will acknowledge your report as soon as possible.
- We will investigate the issue and keep you informed of our progress.
- Once a fix is ready, we will work with you to agree on a coordinated disclosure date if needed.
We ask that you refrain from public disclosure until we have had a reasonable opportunity to address the issue and release a fix.
This policy applies to the QuickStack project and its official releases. Third-party components and dependencies are handled through their own security reporting processes; if you find an issue in a dependency, please report it to the respective project.
Security fixes are applied to the current release line. If you are running an older version, we recommend upgrading to the latest release to receive security updates.
Thank you for helping keep QuickStack and its users safe.