We welcome reports from the security community and are committed to working collaboratively to investigate and resolve vulnerabilities responsibly.
If you find a security vulnerability please submit details through our bug bounty program [FAQ]. Always submit potential security vulnerabilities via the webform; never submit security-related bugs through a Github Issue or by email.
To help us triage quickly, please provide:
- A clear description of the issue
- Steps to reproduce (or a proof of concept)
- Affected versions / environments
- Potential impact (what an attacker could achieve)
- Any suggested mitigations or fixes
Other bugs, that have no potential security implications, can be submitted via our addons issue tracker.