This document defines how ExecuTrace handles vulnerability advisories.
- Receive private report
- Triaging and severity assessment
- Patch development and review
- Coordinated release
- Public advisory publication and attribution
- Critical: Remote execution, full compromise
- High: Privilege escalation, data exposure
- Medium: Significant abuse with constraints
- Low: Limited impact
Contributors and researchers who responsibly disclose verified vulnerabilities are added to:
website/data/security_hof.json- website Security Hall of Fame section
- Title
- Affected versions
- CVSS/severity
- Technical summary
- Reproduction
- Mitigation
- Fixed version
- Credits