ROV is early-stage software. Security fixes will be applied to the latest main branch first.
Please do not open public issues for security vulnerabilities involving:
- Authentication bypass
- Unauthorized remote control
- Input injection escalation
- Tailscale or network exposure misconfiguration guidance
- Sensitive data leakage
Instead, report vulnerabilities privately through GitHub Security Advisories for this repository once the GitHub repo is live.
When reporting, include:
- A clear description of the issue
- Impact and attack preconditions
- Reproduction steps
- Any logs, screenshots, or proof-of-concept details needed to verify safely
We will acknowledge valid reports as quickly as possible and coordinate a fix before public disclosure when appropriate.