Report privately through GitHub Security Advisories. Do not open a public issue.
Expect an acknowledgement within 72 hours and an assessment within a week. Please give us 90 days before public disclosure, or less if the issue is already being exploited.
Until 1.0, only the latest release gets fixes.
In scope: authentication and session handling, app passwords, share link tokens, path handling in the node tree and the WebDAV layer, quota and refcount accounting, and anything that lets one tenant reach another tenant's blobs.
Out of scope: findings that require an already-compromised host, denial of service through unbounded upload size on a deployment that has not configured a reverse-proxy limit, and reports generated by a scanner with no demonstrated impact.