Security fixes are applied to the latest release and the main branch.
Pre-release and older versions may not receive fixes.
Please use GitHub's Security tab to submit a private vulnerability report. Do not open a public issue containing exploit details, credentials, private recordings, transcripts, or other sensitive data.
Include the affected version, operating system, reproduction steps, impact, and any suggested mitigation. You should receive an acknowledgement within seven days. If private vulnerability reporting is unavailable, open a minimal public issue asking the maintainer for a private contact channel without disclosing the vulnerability.
Meeting audio, transcripts, speaker labels, and API tokens can all be sensitive. Before sharing diagnostics, remove recordings, transcript content, tokens, personal information, and identifying file paths.