Please report vulnerabilities privately via GitHub Security Advisories. Do not open a public issue for exploitable bugs.
- Authentication and session handling
- XSS in notes, reports, or Markdown
- Privilege escalation on
/admin - Sandbox escapes in the practice engines
- YouTube’s own player
- Third-party resource sites
- Social engineering of Discord members
We will not add video downloaders, custom YouTube players, or server-side execution of untrusted code.