Please do not report security vulnerabilities in a public GitHub issue.
Use GitHub's private vulnerability reporting for this repository:
https://github.com/Drenzzz/ADBKit/security/advisories/new
If private reporting is unavailable, contact the repository maintainer privately through GitHub before publishing details.
Security reports may include issues involving:
- Shell or command injection
- Unsafe path handling or path traversal
- Untrusted binary downloads or package extraction
- Unexpected privilege escalation
- Secrets exposed by the application or CI
- Device data exposed to the wrong local process or path
Include the affected version or commit, a short description, reproduction steps, and the impact. Do not include real credentials, private device data, or a complete public exploit while the issue is being reviewed.
This policy covers ADBKit. Vulnerabilities in ADB, Fastboot, scrcpy, Wails, or other upstream projects should be reported to their respective maintainers.