Do not open a public GitHub issue for security vulnerabilities.
Report privately to: blackcatacademy@protonmail.com
Include:
- affected component (
BlackCat\\Core\\Database,KeyManager, …) - impact and severity estimate
- a minimal reproduction (if possible)
- suggested fix or mitigation (if you have one)
Security fixes are provided for the latest stable release and the active development branch.