Please report vulnerabilities privately to the maintainers through GitHub Security Advisories. Do not open a public issue for an undisclosed vulnerability. Include affected versions, reproduction steps, impact, and suggested mitigation. Maintainers will acknowledge reports as promptly as possible and coordinate disclosure after a fix is available.
Only the latest release receives security fixes. Relaybox is intended for trusted development and operator environments; review the threat model before network exposure.