Nebulynk security reports must be handled confidentially. Do not publish exploit details, deployment information, credentials, or affected-user data in public issues or discussions.
Use either of these private channels:
- GitHub Private Vulnerability Reporting from this repository's Security tab, when it is enabled.
- Email info@nebulynk.net with the subject
Nebulynk security report.
Please include the affected version or commit, reproduction steps, expected impact, and sanitized logs or proof of concept. Do not send passwords, API keys, access tokens, or unredacted production data.
The public self-hosted release covers the backend API and realtime behavior, browser frontend, self-hosting configuration, supporting data services, media integration, and the optional Windows push-to-talk helper.
Before exposing an instance publicly, review: