# Security Policy ## Supported Versions Security fixes are provided for the latest released version of XC_VM. Please upgrade to the most recent release before reporting an issue. | Version | Supported | | ------------------ | ------------------ | | Latest release | :white_check_mark: | | Older releases | :x: | ## Reporting a Vulnerability **Please do not report security vulnerabilities through public GitHub issues.** For critical vulnerabilities (RCE, authentication bypass, privilege escalation, data leakage), use private disclosure via **GitHub Security Advisories**: - https://github.com/Vateron-Media/XC_VM/security/advisories/new For lower-severity issues that are safe to disclose publicly, you may use the [Security Vulnerability issue template](https://github.com/Vateron-Media/XC_VM/issues/new?template=security.yml). ### What to include - A description of the vulnerability and its impact. - Steps to reproduce (proof of concept where possible). - Affected version / build type (MAIN or LoadBalancer) and environment. - Any suggested remediation. ### What to expect - **Acknowledgement** of your report within a few days. - An initial assessment and severity classification. - Coordinated disclosure: we will work with you on a fix timeline and credit you in the advisory unless you prefer to remain anonymous. Please give us a reasonable amount of time to address the issue before any public disclosure.