If you've found a security vulnerability, please do not open a public issue. A public report tells attackers about the hole before we can close it.
Email security@streamelements.com with:
- What you found and where.
- Steps to reproduce it.
- What an attacker could do with it.
We'll confirm we got your report, keep you posted while we fix it, and credit you if you'd like once it's resolved.
- Don't post the problem in a public issue, Discord, or anywhere else public.
- Don't access, change, or delete data that isn't yours while testing.
- Don't run attacks that degrade the service for other users.