Lenswire is a local HTTP(S) inspector (MITM with a user-installed CA). Do not use it to intercept traffic without consent.
Please do not open a public issue for sensitive reports.
Prefer one of:
- GitHub Security Advisories (private disclosure)
- Email the maintainer: dmitryshelomanov@mail.ru (same contact as in-app feedback /
package.json)
Include impact, affected platforms (iOS/Android), and steps to reproduce if possible. You should get an acknowledgment when the report is seen; timing depends on maintainer availability.
- Loopback-only listeners and user-controlled CA install are intentional product behavior.
- Certificate pinning bypass is out of scope for Lenswire itself.