Report suspected vulnerabilities privately to contact@modlabs.cc. Include affected versions, impact, reproduction steps, and any proposed mitigation.
Do not include credentials, private server data, or player data. Please allow the maintainers time to investigate and publish a coordinated fix before public disclosure.
Only the current Paper 26.2 development line receives security fixes.