| Version | Supported |
|---|---|
| 1.0.x | Best-effort security review |
| < 1.0 | No |
PrompterKit 1.0.x is feature-complete and in maintenance mode. No feature development or Camera Hub compatibility tracking is planned. Security reports against 1.0.x may be reviewed and addressed as maintainer capacity allows.
Please report security issues privately via GitHub Security Advisories:
https://github.com/snapsynapse/prompter-kit/security/advisories/new
Do not open a public issue for security reports.
There is no guaranteed response, fix, or remediation timeline. A private report is welcome but does not create a commitment to issue a patch. Forks may provide continued support; assess their provenance independently.
PrompterKit writes to the Camera Hub data directory on the local machine and produces backup zip archives. In-scope reports include:
- Path traversal or zip-slip during
restore - Arbitrary file write outside the Camera Hub data directory
- Corruption of
AppSettings.jsonthat is not recoverable - Code execution triggered by a crafted
.txt,.md, or backup zip - Remote code execution via the local web GUI (Flask app)
Out of scope:
- Issues requiring the attacker to already have write access to the Camera Hub data directory
- Vulnerabilities in Elgato Camera Hub itself
- Denial of service against a local-only server bound to
127.0.0.1