Security fixes are made on the latest release and the main branch.
Please use GitHub's Security > Report a vulnerability form instead of a public issue. Include the affected version, operating system, reproduction steps, and the impact you observed. You should receive an acknowledgment within seven days.
Do not include camera passwords, private IP addresses, or captured video in a
report. GrowCam PC is designed for trusted local networks and does not provide
dashboard authentication. A non-loopback web bind therefore requires the
explicit --allow-remote option.