Skip to content

Security: Worklenz/worklenz

SECURITY.md

Security Policy

Supported Versions

We provide security updates for the following versions of Worklenz:

Version Supported
3.x ✅
2.x ❌
< 2.0 ❌

Reporting a Vulnerability

The Worklenz team takes security issues seriously and welcomes reports from security researchers and the community.

How to Report

Please do not report security vulnerabilities through public GitHub issues, discussions, or social media.

Instead, please use one of the following private channels:

  1. GitHub Private Vulnerability Reporting (Preferred):
    Submit a private report directly through GitHub at:
    👉 New Advisory Report

  2. Email:
    If you are unable to use GitHub Private Advisories, you can contact the maintainers via email at:
    📧 security@worklenz.com


What to Include

To help us triage and resolve the issue quickly, please include:

  • A clear description of the vulnerability and its potential impact.
  • Step-by-step instructions or proof-of-concept (PoC) code to reproduce the issue.
  • Affected components (backend, frontend, client portal, API endpoints, or database).
  • Any proposed remediation or patches, if available.

Response Timeline

  • Initial Acknowledgment: Within 48 hours of receipt.
  • Triage & Status Update: Within 5 business days.
  • Fix & Public Disclosure: We aim to release patches for confirmed vulnerabilities within 14 to 30 days, coordinated with the reporter.
Learn more about advisories related to Worklenz/worklenz in the GitHub Advisory Database