If you discover a security vulnerability, please report it responsibly.
Do not at first open public issues for security vulnerabilities.
- First, report the issue through Email: cristian.chiriac02@stud.acs.upb.ro
- If you get no response after 48 hours, open a GitHub Issue
To help us triage and resolve the issue quickly, please include:
- A clear description of the vulnerability
- Steps to reproduce the issue
- Potential impact and attack scenarios
- Any proof-of-concept code or screenshots (if applicable)
- Suggested fixes (optional, but appreciated)
This project allows users to self-host a web interface for viewing camera feeds from Android devices and ESP32-based cameras. Security considerations include, but are not limited to:
- Unauthorized access to camera feeds
- Weak authentication or misconfiguration
- Exposure of video streams over insecure networks
- API or endpoint vulnerabilities
- Device-level security risks (Android / ESP32 firmware interactions)
- We aim to acknowledge receipt of vulnerability reports within 48 hours
- We will provide an estimated timeline for a fix after initial assessment
- Once resolved, we may credit you in the release notes (unless you prefer to remain anonymous)
Security fixes will be released as soon as possible and documented in:
- Release notes
- Commit history
This is a self-hosted project. The maintainers are not responsible for:
- Misconfiguration by users
- Insecure deployment environments
- Compromised devices (Android or ESP32)
- Data exposure due to improper security practices
Thank you for helping keep this project and its users safe.