Report a vulnerability
Please do not open a public issue. Instead use GitHub private vulnerability reporting or email anisnur19315@gmail.com with steps to reproduce. You will get an answer within a few days, and credit in the release notes unless you prefer otherwise.
Worth reporting
- Recordings, audio or input logs leaving the machine
- Capture or the input hook continuing after Stop
- File read or write outside expected folders through a crafted
.vuoomproject - Any network request other than the two listed below
What the app does on the network
- An update check against GitHub Releases on launch. Updates are signed; the public key is pinned in the app.
- A one-time captions model download from Hugging Face, verified by SHA-256, only when you ask for captions.
Plus a local connection on 127.0.0.1 between the editor and the engine.
Supported versions
Only the latest release receives fixes. Vuoom updates itself, so updating is the patch.
Builds
Every installer is built by GitHub Actions from the public source. The workflow is in release.yml. Installers are not yet Authenticode-signed, which is why SmartScreen warns.