Security and system integrity are paramount at UMO-Core. We welcome security researchers to audit our codebase.
If you identify a security flaw (e.g., credential exposure, SQL injection, unauthorized RCE), please do not disclose it publicly.
- Reporting Channel: Open a confidential Issue tagged as
SECURITY-AUDITor contact the maintainer directly.
- Media discovery API handling.
- Database persistence layer.
- Web Admin Dashboard (XSS/CSRF).
- Misconfiguration of local
.envfiles by users. - Third-party dependency vulnerabilities (upstream issues).
Our Red Team will acknowledge the report within 48 hours and provide a remediation ETA.
Thank you for securing the Media Orchestrator.