If you find a security vulnerability in SMB Mounter (e.g. a way to read stored credentials, a weakness in the network scan, or an issue with permission handling), please do not report it as a public GitHub issue.
Instead, contact the repository owner directly via GitHub (a private message or the contact form linked in the GitHub profile). If possible, please include:
- The affected program version/commit
- A short description of the vulnerability and its impact
- Steps to reproduce, if available
When connecting network drives, SMB passwords are passed exclusively via the
Windows API WNetAddConnection2 (via pywin32) as a function parameter in
process memory – never as a command line argument of an external process (e.g.
net.exe). This means they are not briefly visible to other processes with
sufficient privileges via process inspection tools (Process Explorer, WMI
Win32_Process.CommandLine, ETW tracing).
The following are considered security vulnerabilities in particular:
- Storage or transmission of credentials (usernames, passwords) outside Windows Credential Manager
- Ways to gain access to systems through the program that you're not authorized to access
- Unintended data transmission to third parties beyond the MAC vendor lookup described
in
PRIVACY.md
The following are not considered security vulnerabilities in the strict sense: general bugs, UI issues, or compatibility questions – please file a regular issue for those.
Since this is a single-maintainer project without parallel maintained version
branches, security fixes are provided exclusively for the main branch.