Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Reports about security issues should be sent to security[@]openscad.org.
Fully automated reports will be binned directly.
There is no bounty program active for reporting security issues.
When reporting a vulnerability, please include:
- A clear and detailed description of the issue
- The reason why you believe it is a security issue
- The affected platform and version/commit/tag
- Reproduction steps and/or a proof of concept
- Any relevant information like logs, screenshots, ...
- The potential impact
- Suggested mitigations or fixes