Please report security vulnerabilities in webforJ privately — don't open a public issue, discussion, or pull request.
Use GitHub's private vulnerability reporting: open the repository's Security tab and click "Report a vulnerability", or go directly to https://github.com/webforj/webforj/security/advisories/new. Reports are visible only to the maintainers.
To help us triage quickly, please include where you can:
- the affected webforJ version(s) and environment
- a description of the issue and its impact
- steps to reproduce or a minimal proof of concept
We'll follow up with you in the advisory thread. Please keep the details private until a fix has been released.