Please don't open a public issue for security problems. Use GitHub's private reporting instead: Security → Report a vulnerability on this repo.
Include what you found, how to reproduce it, and what version you ran. You'll get a reply within a week.
- Getting into the dashboard or API without a valid login
- An operator doing admin-only things
- Anything that makes the logger transmit or send commands to Asterisk beyond connect, disconnect, and list links
- Command injection through node numbers or other input
- Keep the dashboard on your LAN or a VPN. If it faces the internet, put it behind HTTPS and set
COOKIE_SECURE=1. - Give the AMI user only
commandrights andpermitonly the logger's address. - Keep
.envprivate. It holds your AMI secret.