Security fixes target the latest published ZFileConverter release.
Please do not disclose a suspected vulnerability in a public issue. Use GitHub's private vulnerability-reporting flow:
https://github.com/ZaidNAlAsali/ZFileConverter/security/advisories/new
Include:
- the affected version;
- a concise reproduction;
- expected impact;
- whether Explorer, shell registration, installer elevation, file paths, or conversion tools are involved;
- any proposed mitigation.
Do not include real private documents, media, credentials, certificates, or sensitive system data. A minimal synthetic reproduction is preferred.
Reports involving unsafe path handling, unintended source-file changes, shell-extension stability, installer privilege boundaries, update integrity, or command injection are especially valuable.