Do not report security vulnerabilities through public GitHub issues.
Please disclose vulnerabilities privately by emailing the maintainers. We will:
- Acknowledge receipt within 48 hours
- Provide an estimated fix timeline within 7 days
- Credit you in the release notes (unless you prefer anonymity)
- SQL injection via IPC commands
- Path traversal in file scanner
- Arbitrary code execution via sidecar process
- Private album password bypass
- Issues in dependencies (report upstream)
- Denial of service on local machine