If you discover a security vulnerability in this project, please report it responsibly:
- Do not open a public issue
- Email the maintainer or use GitHub's private vulnerability reporting
- Include steps to reproduce and any relevant details
The maintainer responds within 72 hours and works to release a fix promptly.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Older releases | No |
This addon runs locally on your Kodi device and communicates only with services you configure: your search provider (NZBHydra2, Prowlarr, or direct Newznab indexers) and your backend (nzbdav, InfiniDysk, or NZBGet). Security concerns include:
- API key handling and storage
- WebDAV, NZBGet, and SMB (Windows/Samba file sharing) credential management
- URL construction and validation
- XML parsing of search-provider and WebDAV responses (see
resources/lib/xml_safety.py)