Please do not report security vulnerabilities through public GitHub issues.
Instead, please report them via email to contact@abnt.it or here.
You should receive a response within 48 hours. If for some reason you do not, please follow up via email to ensure we received your original message.
To help us respond effectively, please include:
- Type of vulnerability (e.g., exploit, bypass, crash, etc.)
- Impact of the vulnerability
- Steps to reproduce the vulnerability
- AetherAC version affected
- Server platform and version (Paper/Purpur/Folia/Spigot/etc.)
- Any relevant logs or packet captures (remove sensitive information)
We follow a responsible disclosure process:
- Initial report — Vulnerability submitted via email
- Acknowledgment — Confirmation of receipt within 48 hours
- Validation — Investigation and verification of the vulnerability
- Fix development — Development of a fix (priority based on severity)
- Release — Patch released with security advisory
We aim to release fixes as quickly as possible, but timelines depend on the complexity and severity of the vulnerability.
Security vulnerabilities fixed in releases will be published as GitHub Security Advisories. We will credit reporters unless they wish to remain anonymous.
| Version | Supported |
|---|---|
| Latest stable release | ✅ |
| Previous major version | |
| Older versions | ❌ |
AetherAC contains no backdoors, hidden features, or telemetry that collects personally identifiable information.
If you have questions about this security policy, please email contact@abnt.it.