Please do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting for this repository if it is available. If it is not available, contact the maintainer through the repository owner's GitHub profile and include:
- A short description of the issue.
- Steps to reproduce or a proof of concept.
- The affected platform and usbtree version or commit.
- Any relevant logs or terminal output.
You should receive an acknowledgement within 7 days. Fix timing depends on impact and complexity.
Security-sensitive areas include release artifacts, checksums, installer behavior, USB device parsing, and any path or configuration handling.