SECURITY.md 887 B

Security Policy

Reporting a vulnerability

Do not open a public issue for anything you believe is exploitable — an authentication bypass, remote code execution, injection, secret or credential exposure, privilege escalation. A public report gives attackers a head start against every 3x-ui deployment.

Instead, use GitHub's private vulnerability reporting: open this repository's Security tab and click Report a vulnerability. Include the affected 3x-ui version, reproduction steps, and the impact you see. You will receive replies in the advisory thread.

There is no bug-bounty program. Fixes ship in the next release, and the advisory is published after a fixed version is available.

Supported versions

Only the latest release receives security fixes. Update with the install script or your package channel and confirm the problem still exists before reporting.