Security fixes are released for the latest published Engine version. Customers should run pinned release versions and upgrade when a security release is published.
Report suspected vulnerabilities privately to your Fused security contact or
to security@usefused.com.
Please include:
- affected version or commit
- deployment mode, such as binary, embedded Docker image, or headless Docker image
- steps to reproduce
- impact assessment
- logs or traces with secrets removed
Do not open a public issue for credential leaks, authorization bypasses, remote-code execution, secret storage weaknesses, or supply-chain concerns.
Fused will acknowledge reports, investigate, and coordinate remediation with affected customers before publishing public details where appropriate.