Wisely

Security policy

Supported versions

Only the current major version receives security fixes.

VersionSupported
2.xYes
1.xNo

1.x no longer receives any updates, including security fixes. Upgrading to 2.x is strongly recommended.

Reporting a vulnerability

If you find a security vulnerability in this project, please do not open a public issue.

  1. 1Open a private report via the Security > Advisories tab of this GitHub repository
  2. 2Describe the vulnerability in as much detail as possible: the component involved, reproduction steps, potential impact, and the affected version
  3. 3If you can, suggest a fix or a direction for resolving it
Open a private report via GitHub Security Advisories

Response times

StepEstimated delay
Acknowledgment48 hours
Initial assessment (accepted / rejected)7 days
Fix published30 days

These delays are indicative and may vary depending on the complexity of the vulnerability.

In scope

  • Arbitrary code execution via manipulation of data/profiles.json or .wslconfig
  • Privilege escalation related to the Windows scheduled tasks created by -Monitor start
  • Bypassing input validation (e.g. -NewProfile, -Import)
  • Sensitive data leakage in logs or generated reports

Out of scope

  • Vulnerabilities in Windows, PowerShell, or WSL2 itself
  • Issues caused by a non-standard or intentionally insecure system configuration
  • Code style or readability issues

Responsible disclosure

We commit to:

  • Treating every report seriously and confidentially
  • Notifying the reporter once a fix has shipped
  • Crediting the reporter in the changelog (unless they ask otherwise)

Please give us the time needed to fix a vulnerability before any public disclosure.