The latest published FiwNode release receives security fixes. Earlier versions may need to upgrade to receive a fix.
Do not post exploit details in a public issue. Use GitHub's private vulnerability report for this repository, or contact @Fi3w0 privately.
Include the FiwNode version, distribution, relevant PipeWire/Qt/FFmpeg versions, the smallest safe reproduction, and the potential impact. Remove personal audio, filenames, tokens, and home-directory paths unless they are essential to reproduce the problem.
We aim to acknowledge reports within one week and address confirmed issues according to severity; a fix may require a new release. The project runs a local IPC socket, starts FFmpeg for local files, reads a SQLite library, and can use input-device access for hotkeys, so reports affecting these boundaries are especially useful.