Security fixes are made against the current release and the default branch. Older builds may require an update before a fix can be applied.
Please do not open a public issue for a suspected vulnerability. Email Visual MD support with a concise description, affected version, reproduction steps, and impact. Do not attach private Markdown libraries or credentials; use the smallest safe example that demonstrates the issue.
You should receive an acknowledgement within three business days. The report will be investigated before details are made public, and credit will be given when requested unless doing so would expose the reporter.