Security matters, even for a container project. This policy describes how to
report vulnerabilities affecting mt5-docker and how they are handled.
Only the latest main branch and the most recent release receive security
fixes. There are no backports to older versions. Please make sure you can
reproduce the issue against the current main before reporting.
Please report security issues privately, not as a public issue. Two channels:
- GitHub private vulnerability reporting (preferred). Open the Security tab of the repository and click "Report a vulnerability". This keeps the report private to the maintainers and does not expose your email address.
- Email fallback. Send the report to
1905197+davalillo@users.noreply.github.com. Note that this is the GitHub noreply address; for sensitive reports, prefer GitHub private reporting since it does not expose your email.
- Acknowledgement of receipt: within 72 hours.
- Initial assessment: within 7 days.
- Fix timeline: depends on severity and impact. We will agree on a publication date with the reporter before any fix is released.
- A description of the vulnerability and its potential impact.
- Steps to reproduce, including any relevant configuration.
- Affected versions / commits.
- A suggested fix, if you have one.
In scope:
- The Docker image,
Dockerfile, scripts, and runtime configuration.
Out of scope (report these upstream, not here):
- Vulnerabilities in third-party software packaged inside the image: Wine, MetaTrader 5 itself, KasmVNC, or the LinuxServer base image. Report those to their respective upstream projects.
The MetaQuotes demo account (Login=5053564303) used by this image is a free,
anonymous demo account. It is not a security concern and is not in scope.
We ask for coordinated disclosure. Once a fix is available we will publish a security advisory and credit the reporter, unless they prefer to remain anonymous.