We take the security of World of ClaudeCraft seriously, and we appreciate the work of everyone who helps keep players and self-hosters safe.
Please do not report security vulnerabilities through public GitHub issues, pull requests, or Discord. Public disclosure before a fix is available puts players and people running their own servers at risk.
Instead, report privately using one of these channels:
- GitHub private advisory (preferred). Go to the Security tab and open a draft advisory. This keeps the report private between you and the maintainers until a fix is ready.
- Discord. If you can't use GitHub advisories, send a private message to a member of the Levy St, Admin, or Devs group on the community Discord and ask for a secure way to share the details.
Please include as much as you can:
- What the issue is and the kind of impact you think it has.
- Steps to reproduce, or a proof of concept.
- Affected area (offline client, online server, authentication, moderation, database, and so on) and any relevant versions or commits.
- We'll acknowledge your report as quickly as we can, normally within a few days.
- We'll keep you updated as we investigate and work on a fix.
- Once a fix is released, we're glad to credit you for the discovery, unless you'd prefer to stay anonymous.
We ask that you give us a reasonable amount of time to release a fix before any public disclosure, and that you avoid accessing or modifying other people's data, degrading the service, or running tests against the live multiplayer servers without permission.
World of ClaudeCraft is under active development and is currently pre-1.0. Security
fixes land on the main branch and ship in the next release, so the most recent
release and the current main are the supported targets. If you run a self-hosted
server, please keep it up to date.
Thank you for helping keep the community safe.