Security fixes are released for the latest published version. Always run the most recent release.
| Version | Supported |
|---|---|
| Latest | ✅ |
| Older | ❌ |
Report it privately through GitHub's private vulnerability reporting ("Report a vulnerability" on the Security tab). Never in a public issue.
Especially valued: one user reading or changing another user's data, bypasses of login, 2FA or passkeys, leaked API keys or sessions, and webhooks that reach internal hosts.
You may test Momo and report what you find. There is no payment: Momo is a volunteer project, and every report serves the people who rely on it. With your consent, we credit you in the advisory and below. Test on your own installation, never on other people's.
| Step | Within |
|---|---|
| Acknowledge your report | 48 hours |
| Assess it and tell you the plan | 7 days |
| Release a fix for a critical or high issue | 14 days |
Momo is maintained in spare time; these are commitments, and when one slips you hear why.
None yet.