Skip to content
MisterShell

Vulnerability Disclosure Policy

Last updated: 2026-08-28

MisterShell sits on the privileged-access path to your infrastructure, so we want to hear about security weaknesses in it as early as possible. This policy explains what is in scope, how to reach us, and what you can expect from us when you do. It is written for security researchers and for the security teams of organizations that run MisterShell.

1. Scope

The following are in scope:

The following are out of scope:

If you are unsure whether something is in scope, report it anyway and say so — we would rather triage a borderline report than miss a real one.

2. How to report

Email security@mistershell.com. This address is for security reports only; for anything else, see section 9. A machine-readable copy of this contact is published at /.well-known/security.txt.

We do not currently publish a PGP key. If your report contains sensitive details, tell us in a first message and we will arrange a secure channel before you send them.

3. What to include

Reports that let us reproduce the issue quickly get fixed quickly. Please include:

4. What we commit to

5. Coordinated disclosure

We ask that you give us the opportunity to fix a vulnerability before you publish it, and that you do not share it with third parties in the meantime. We will not ask you to withhold publication indefinitely: once a fix is released, or 90 days after confirmation, whichever comes first, you are free to publish. We are happy to agree on a joint disclosure date.

6. Safe harbor

If you make a good-faith effort to comply with this policy, we will not pursue or support legal action against you for your research. Good faith means you act within the scope above, avoid privacy violations, data destruction, and service disruption, do not access or retain data beyond what is needed to demonstrate the issue, and give us reasonable time to respond before disclosing.

Test against your own MisterShell installation. Do not test against installations you do not own or are not authorized to test.

7. No bug bounty

We do not run a bug bounty program and do not pay for reports today. We say so plainly so that nobody is surprised. What we do offer is a responsive, technical counterpart who will take your report seriously and credit your work.

8. How fixes reach you

Security fixes ship in regular MisterShell releases. When a report leads to a fix, we tell the reporter which version contains it and describe the issue in that release's notes. We do not currently operate a security-advisory mailing list and are not a CVE numbering authority; where a report warrants a CVE, we will work with the reporter to request one.

MisterShell never phones home, so it cannot notify your installation of a fix. Keep an eye on releases and upgrade promptly.

9. Everything else

For product questions, bugs that have no security impact, licensing, and deployment help, use the support portal at mistershell.zohodesk.eu. Privacy questions go to privacy@mistershell.com; legal questions to legal@mistershell.com.

10. Changes to this policy

We may update this policy from time to time. When we do, we will revise the "Last updated" date above and the expiry date in security.txt.