Security updates are provided for the latest released version.
| Version | Supported |
|---|---|
| 0.1.x | Yes |
| Older or unreleased builds | No |
Please use the repository's Security → Report a vulnerability form. Do not disclose an unpatched vulnerability in a public issue.
Include the affected version, operating system, a minimal reproduction, the expected impact, and whether a write-capable command was involved. Remove personal paths and account information.
Never attach paid/private VARs, authentication material, personal VaM logs, or a real backup manifest. Build a synthetic reproducer or offer to coordinate privately if the issue cannot otherwise be demonstrated.
You should receive an acknowledgment within seven days. Confirmed issues will be assessed, fixed, and disclosed in proportion to their impact.
Unexpected replacement, archival, restore, or data-integrity behavior is security-sensitive even when it is not an exploit. Stop using the affected build, keep VaM closed, preserve the backup directory and reports, and report the issue privately before attempting further cleanup.