Security fixes are currently applied to the latest source on the default branch. The project has not yet reached a stable 1.0 release.
Please use GitHub's private vulnerability-reporting feature when available. Do not disclose an exploitable issue publicly before maintainers have had reasonable time to investigate and prepare a fix.
Include:
- affected component and version or commit;
- reproduction steps or a minimal proof of concept;
- expected impact;
- suggested mitigation, when known.
WinChess can launch an executable selected by the user. It does not sandbox imported engines. Only run trusted UCI programs, because they execute with the current user's permissions.