We take the security of Orchestrator seriously. Because Orchestrator provisions and controls fleets of devices, we especially appreciate responsible disclosure.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report them privately using GitHub's private vulnerability reporting (Security → Report a vulnerability on this repo).
Please include:
- A description of the vulnerability and its potential impact.
- Steps to reproduce (proof-of-concept if possible).
- Affected versions / components (app, agent, netboot, etc.) if known.
- We aim to acknowledge your report within 3 business days.
- We'll keep you updated on our progress and coordinate a disclosure timeline with you.
- We're happy to credit you once the issue is resolved, if you'd like.
Thank you for helping keep Orchestrator and its users safe.