Security fixes are provided for the latest published release.
Please do not open a public issue for a suspected vulnerability. Use GitHub's Report a vulnerability flow in the repository Security tab so credentials, host details and reproduction steps remain private.
Include the affected version, impact, reproduction steps and any suggested mitigation. You should receive an acknowledgement within seven days.
XYSSH encrypts saved passwords with Electron safeStorage when the operating system encryption service is available. If it is unavailable, passwords are intentionally not persisted. Private keys and passwords should never be included in issues, logs or screenshots.