Security updates and vulnerability patches are actively maintained for the following versions:
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0.0 | ❌ |
We take the security of Media Studio Hub very seriously. If you discover a potential security vulnerability, please do NOT open a public issue.
- GitHub Private Vulnerability Reporting (Preferred): Navigate to the Security Tab of this repository and click Report a vulnerability.
- Direct Contact:
Alternatively, email the maintainer at
concepcion.fam@gmail.comwith the subject[SECURITY] Media Studio Hub Vulnerability.
- A clear description of the vulnerability and its potential impact.
- Step-by-step reproduction instructions or a minimal Proof of Concept (PoC).
- Any relevant logs, request payloads, or system details.
- Initial Response: Within 24-48 hours acknowledging receipt.
- Assessment & Fix: Vulnerability triage and patch development within 5-7 business days.
- Coordinated Disclosure: A security advisory and release patch will be published jointly once resolved.
Media Studio Hub implements multiple layers of backend hardening:
- Path Traversal Protection (
_safe_path): All file operations are strictly sandboxed within authorized directories. - Least-Privilege Subprocess Execution: Strict process-group management (
killpg) to eliminate orphaned child tasks. - Input Sanitization: Whitelisted character filtering on file paths, playlist names, and tag metadata.