Skip to content

Security: arakiken/mlterm

SECURITY.md

Security Policy

Thank you for helping to keep mlterm secure. We take security seriously and appreciate your efforts to responsibly disclose any vulnerabilities you find.

Supported Versions

Security updates and bug fixes are actively provided for the latest stable release line. If you are using an older version, we strongly recommend upgrading to the latest release.

Version Supported
3.9.5 ✅ Yes
< 3.9.5 ❌ No

Reporting a Vulnerability

Please do not report security vulnerabilities via public GitHub Issues, Pull Requests, or public forums.

To report a vulnerability safely and confidentially, please use GitHub Private Vulnerability Reporting:

  1. Go to the Security tab of this repository.
  2. Select Advisories on the left sidebar.
  3. Click Report a vulnerability to securely submit your report.

Please include the following details in your report:

  • Description: A brief summary of the vulnerability (e.g., buffer overflow, crash via specific escape sequence).
  • Impact: The potential impact of the flaw (e.g., Denial of Service, Remote Code Execution).
  • Steps to Reproduce: Clear instructions, commands, or a Proof of Concept (PoC) to reproduce the issue.
  • Environment: The version of mlterm, compiler, options used for building, and the operating system/window system (e.g., X11, Wayland, Win32).

There aren't any published security advisories