Security fixes are provided for the latest released version of axoned and
the currently supported AXONE network releases.
Please upgrade to the latest available release before reporting an issue. We may still assess reports affecting unsupported versions when the vulnerability also affects a supported version.
Please report security vulnerabilities privately through GitHub Private Vulnerability Reporting.
Thank you for helping to keep the AXONE ecosystem safe!
Do not report vulnerabilities through public GitHub issues, pull requests, Discord, or social media.
Include, where possible:
- a clear description of the vulnerability and its potential impact;
- affected versions, commits, configuration, or deployment conditions;
- reproducible steps or a minimal proof of concept;
- logs, transaction hashes, or other relevant evidence;
- suggested mitigations, if known.
Do not include private keys, seed phrases, credentials, production secrets, or personal data in a report.
We will review reports as soon as we can, but cannot guarantee a response or remediation timeframe.
If the report is accepted, we will investigate it, coordinate a fix and disclosure with the reporter where practical, and credit the reporter in a published advisory if they wish.
Please do not disclose the vulnerability publicly while we assess the report.