Report vulnerabilities in 0sec to security@0sec.ai. Do not open a public issue for a suspected security flaw.
Include:
- a clear description of the issue;
- reproducible steps or a minimal test case;
- affected version or commit;
- potential impact and any mitigations already attempted.
Do not include customer data, production credentials, or exploit material for third-party systems without authorization.
Security fixes are made against the latest tagged 0sec release. If you build from source, include the commit hash in your report.
We coordinate fixes and disclosure with reporters where practical. Public advisories are published only after a fix or mitigation is available.