Security fixes are provided for the latest published release. Older versions may be asked to upgrade before a report is investigated.
Use GitHub private vulnerability reporting for the repository. Do not disclose the issue publicly until a fix is available. Include affected versions, reproduction steps, impact, and any suggested mitigation. Do not attach real savegames, access tokens, private keys, or proprietary Aloft assemblies.
If private vulnerability reporting is unavailable, contact the repository maintainer privately through the contact method listed on their GitHub profile.
The application is designed for local use and binds its HTTP services to loopback addresses only. It must not be exposed through port forwarding, a reverse proxy, a public tunnel, or a non-loopback bind address. Runtime telemetry is read-only. Explicitly enabled waypoint and experimental teleport tools can modify game state through a session-authenticated command endpoint.