This is a community project. Security fixes are provided on a best-effort basis.
If you discover a security vulnerability, please report it responsibly:
- Do not open a public issue with exploit details.
- Instead, open a GitHub issue titled "Security report" with minimal details, and we will follow up.
If the vulnerability is confirmed, we will:
- work on a fix
- publish an update in the repository
- Do not expose this server directly to the public internet without authentication and transport security.
- Treat room URLs as shared secrets.