Please report security issues privately. Don't open a public issue, pull request, forum thread, or Slack message.
- By Email: on security@openmrs.org - Emails are automatically posted on the private Security Talk category, where they are immediately available for review & discussion by relevant OpenMRS community members in technical or operational leadership positions.
- On GitHub: you can use the Private Vulnerability Report feature in GitHub here. This helps us leverage GitHub's Security Advisory & CVE tools. Please include as much detail as possible: the steps to reproduce, the affected versions, the expected vs. actual results, and anything else that helps us react faster. We prefer a text write-up with a proof-of-concept over screenshots or videos.
Please don't test against any system holding real patient data.
For our full vulnerability management process, severity targets, and disclosure steps, see om.rs/security101.