Report a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

To report a vulnerability in EximeeBPMS, use GitHub’s private vulnerability reporting feature:

github.com/EximeeBPMS/eximeebpms/security/advisories/new

This opens a private draft security advisory visible only to the maintainers.

When reporting, please include:

  • The affected component/module and version(s) (e.g. engine, REST API, Cockpit/Admin/Tasklist, eximeebpms-run)
  • A description of the vulnerability and its potential impact
  • Steps to reproduce, or a proof of concept
  • Any known workaround

We acknowledge new reports within 3 business days. See SECURITY.md for our full process, supported versions, scope, and coordinated-disclosure expectations.