Security reports should target the current main branch unless a maintained release branch is documented.
Please report vulnerabilities privately before public disclosure. You can either:
- email
thilo.reintjes+legacyworld@gmail.com, or - open a private advisory via GitHub's Security Advisories on this repository.
Please include:
- affected component and version or commit,
- reproduction steps,
- expected and actual impact,
- any suggested mitigation.
BenchSvc is a VM control service for benchmark automation. It can execute commands and inspect files inside the configured benchmark environment. Treat it as privileged infrastructure and run it only inside isolated benchmark VMs or trusted local networks.