Security policy
Supported versions
Only the current major version receives security fixes.
| Version | Supported |
|---|---|
| 2.x | Yes |
| 1.x | No |
1.x no longer receives any updates, including security fixes. Upgrading to 2.x is strongly recommended.
Reporting a vulnerability
If you find a security vulnerability in this project, please do not open a public issue.
- 1Open a private report via the Security > Advisories tab of this GitHub repository
- 2Describe the vulnerability in as much detail as possible: the component involved, reproduction steps, potential impact, and the affected version
- 3If you can, suggest a fix or a direction for resolving it
Response times
| Step | Estimated delay |
|---|---|
| Acknowledgment | 48 hours |
| Initial assessment (accepted / rejected) | 7 days |
| Fix published | 30 days |
These delays are indicative and may vary depending on the complexity of the vulnerability.
In scope
- Arbitrary code execution via manipulation of data/profiles.json or .wslconfig
- Privilege escalation related to the Windows scheduled tasks created by -Monitor start
- Bypassing input validation (e.g. -NewProfile, -Import)
- Sensitive data leakage in logs or generated reports
Out of scope
- Vulnerabilities in Windows, PowerShell, or WSL2 itself
- Issues caused by a non-standard or intentionally insecure system configuration
- Code style or readability issues
Responsible disclosure
We commit to:
- Treating every report seriously and confidentially
- Notifying the reporter once a fix has shipped
- Crediting the reporter in the changelog (unless they ask otherwise)
Please give us the time needed to fix a vulnerability before any public disclosure.