Only the latest published release receives fixes. Older tags are kept for reference and are not patched.
This module runs as root on the device. Treat the following as security issues rather than ordinary bugs:
- A path that lets a non-root app read, write, or influence module state under
/data/adb/modules/p9pxl_superchargeror/data/adb/supercharger_state - Command injection through WebUI input, log content, or environment values
parsed by
bin/supercharger_ctl.shorservice.sh - Files shipped or created with permissions wider than intended
- A tuning write that disables a thermal or charging safety limit
Report privately through GitHub. Open the repository's Security Advisories page and use Report a vulnerability. Private vulnerability reporting is enabled, so the report stays visible only to you and the maintainer.
Do not open a public issue for a security report.
Include the module version, device codename, root solution, and the smallest reproduction you have. A support snapshot from the WebUI Support tab is useful, but review it first and remove anything you do not want published.
You will get an acknowledgement of the report and, once a fix ships, a note in the changelog. This is a single-maintainer hobby project, so there is no guaranteed response window and no bounty.