Please report issues against the latest GitHub Release. Older package versions are not patched separately.
Use GitHub Security Advisories so the report stays private until a fix is published.
Do not open a public issue for:
- authentication or CAPTCHA bypasses
- ways to trigger unintended Data Privacy deletions
- exploit details, payloads, or proof-of-concept attack steps
Include the IntakeShield version, Zammad version, and a minimal description of the impact.
IntakeShield can queue permanent user and ticket deletions through Zammad’s DataPrivacyTask pipeline. Treat misconfiguration reports that could cause unintended removal of accounts or tickets as security issues.
Keep the master switch off until whitelist, candidate role, delay, and review queues are in place.