We provide security updates for the following versions of Worklenz:
| Version | Supported |
|---|---|
| 3.x | ✅ |
| 2.x | ❌ |
| < 2.0 | ❌ |
The Worklenz team takes security issues seriously and welcomes reports from security researchers and the community.
Please do not report security vulnerabilities through public GitHub issues, discussions, or social media.
Instead, please use one of the following private channels:
-
GitHub Private Vulnerability Reporting (Preferred):
Submit a private report directly through GitHub at:
👉 New Advisory Report -
Email:
If you are unable to use GitHub Private Advisories, you can contact the maintainers via email at:
📧security@worklenz.com
To help us triage and resolve the issue quickly, please include:
- A clear description of the vulnerability and its potential impact.
- Step-by-step instructions or proof-of-concept (PoC) code to reproduce the issue.
- Affected components (backend, frontend, client portal, API endpoints, or database).
- Any proposed remediation or patches, if available.
- Initial Acknowledgment: Within 48 hours of receipt.
- Triage & Status Update: Within 5 business days.
- Fix & Public Disclosure: We aim to release patches for confirmed vulnerabilities within 14 to 30 days, coordinated with the reporter.