Report vulnerabilities privately through GitHub Security Advisories for this repository. Do not include OBS WebSocket passwords, private scene/source names, recording paths, or unpublished video in public issues.
The project intentionally exposes no arbitrary script or raw WebSocket request surface. Treat any bypass of endpoint binding, exact-instance validation, postcondition readback, archive ownership, or secret redaction as security relevant.