Security fixes generally target the latest Retold release and current master. Older releases may not receive separate fixes.
Do not open a public issue for a vulnerability that could harm players, servers, or systems before a fix is available.
Email alex@alexejtusl.cz with subject Retold security report and include:
- affected Retold, Minecraft, NeoForge, and Java versions
- whether clients, dedicated servers, or both are affected
- reproduction steps or a minimal proof of concept
- potential impact and relevant logs or code locations
- whether the information has been shared elsewhere
Remove passwords, tokens, private server addresses, and unrelated personal information. Do not exploit the issue against systems or players you do not own or have permission to test.
The developer will confirm receipt when practical, investigate, and coordinate disclosure if the report is valid. Ordinary crashes and gameplay bugs should use the public bug form.