Security fixes are provided for the latest released version of Upgopher. Reproduce a report against that version when possible.
Contact @gm_eduard privately. Include:
- the affected Upgopher version and operating system;
- a minimal reproduction;
- the expected and observed behavior;
- the security impact;
- logs or screenshots with credentials and private paths removed.
Do not open a public issue before disclosure has been coordinated. You should receive an acknowledgement within seven days. Timelines for validation, a fix, and public disclosure will depend on severity and reproducibility.
Please do not access data that is not yours, disrupt third-party systems, or retain sensitive data while researching a report.