| What you found | Where to report |
|---|---|
| Issue present in official Notepad++ / likely affects everyone | Prefer upstream project’s security process and maintainers; you may also CC the fork contact below |
| Issue only in Logbie fork changes / packaging / agent tooling | Report privately to the fork maintainer (below) |
Do not assume this fork is the official security contact for Notepad++.
Security fixes on this fork are applied at the maintainer’s discretion to the mainline branch and, when practical, to the latest fork tag. Older forks/tags may not receive backports unless explicitly stated here.
Upstream support policy is defined by the upstream project, not by this document.
Please do not open a public issue for security vulnerabilities.
Report privately to:
Include:
- A description of the issue and its impact
- Steps to reproduce or a proof-of-concept (if safe)
- Affected versions / commit SHAs if known
- Whether you believe it is upstream-shared or fork-only
- Any suggested fix (optional)
You should receive an acknowledgment when the report is seen. Timing depends on maintainer availability (this is a maintained-in-the-open fork, not a 24/7 SOC).
If enabled on logbie/notepad-plus-plus, you may use GitHub’s private advisory
flow. Prefer email if you are unsure.
Good-faith security research that:
- Avoids privacy violations, service degradation, and data destruction
- Does not exploit the issue beyond what is needed to demonstrate it
- Reports findings promptly through an appropriate channel above
…is welcome. Do not use findings for extortion or public dump-before-report.
Do not instruct agents to:
- Probe production systems you do not own or lack written authorization to test
- Exfiltrate secrets, dumps, or personal data into chat/logs
- Publish exploit details in public issues before coordinated disclosure
- Write exploit PoCs into this repository
Defensive analysis and hardening patches are encouraged. Recent upstream work on UNC path credential leakage is an example of the kind of fix that belongs here and/or upstream.
The fork maintainer may publish advisories or release notes after a fix is available (or when disclosure is otherwise appropriate). Please allow reasonable time for a fix before public discussion of exploit details. Coordinate with upstream when the issue is shared.