# Security Policy ## Reporting a vulnerability Do not open a public issue for anything you believe is exploitable — an authentication bypass, remote code execution, injection, secret or credential exposure, privilege escalation. A public report gives attackers a head start against every 3x-ui deployment. Instead, use GitHub's private vulnerability reporting: open this repository's **Security** tab and click **Report a vulnerability**. Include the affected 3x-ui version, reproduction steps, and the impact you see. You will receive replies in the advisory thread. There is no bug-bounty program. Fixes ship in the next release, and the advisory is published after a fixed version is available. ## Supported versions Only the latest release receives security fixes. Update with the install script or your package channel and confirm the problem still exists before reporting.