Do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting feature on the repository's Security tab:
https://github.com/BedrockNexus/api/security/advisories/new
Include the affected endpoint or function, reproduction steps, impact, and a minimal proof of concept where appropriate. Remove credentials, access tokens, private server data, signed storage URLs, and personal information from the report.
We will acknowledge reports when reviewed, investigate their impact, and coordinate a fix and disclosure where needed. Please allow a reasonable period for remediation before publishing details.
Security fixes target the current default branch and production deployment. Old forks, historical commits, and unsupported self-hosted modifications are not maintained by the Bedrock Nexus team.