Please do not open a public issue for a security problem. Report it privately through GitHub Security Advisories — "Report a vulnerability" on the affected repo — or by email to jason.schwefel78@gmail.com.
You will get an acknowledgement, and we'll work the fix with you before any public disclosure.
StudioEnsemble products are daemons that control physical hardware over a network-capable control plane (a WebSocket API). By default they bind to loopback with no auth; off-loopback exposure requires coupled authentication (WS-Control Doctrine). A vulnerability can mean unauthorized control of a camera, a light, or a whole rig — so transport, auth, and the control surface are security-sensitive, not just the data.
Pre-beta: the main branch of each product. A support matrix lands at the first release.