Do not open a public GitHub issue for security vulnerabilities.
Send a description of the issue to the maintainer directly. Include steps to reproduce, the potential impact, and any suggested fix if you have one.
Once the issue is confirmed, a fix will be released as quickly as possible and you will be credited in the release notes.
- API endpoints and authentication logic
- Data exposure or leakage
- Dependency vulnerabilities with a known exploit path
Out of scope: rate-limit bypasses on public endpoints, theoretical issues with no practical exploit, and anything related to the Riot Games API itself.