duckboard renders escaped output by default and hashes passwords with scrypt. Report anything that:
- lets template data escape as raw HTML
- leaks session tokens or password hashes
- breaks the JSON error contract
Use GitHub private vulnerability reporting on this repo. Include the
version from package.json.