Use GitHub's Report a vulnerability button under this repository's Security tab. That opens a private advisory only the maintainer can see. Please do not open a public issue for something exploitable.
Expect a first reply within a week. If a fix is needed, the advisory is published together with it.
The latest release. There are no maintained older branches — this is a single folder of scripts. Exit the tray and back up the folder before replacing program files.
Worth knowing before you look for a hole, because it narrows the surface a lot:
- It makes no network connections. Nothing is downloaded, nothing is sent, no telemetry, no update check.
- Nothing is installed. No service, no scheduled task, no registry keys of its own, no elevation. Startup, if you turn it on, is a shortcut in your own Startup folder. Disable startup and exit the tray before deleting the program folder.
- It runs as you, with your privileges, and changes only display configuration, and — when you ask for it — the default playback device and monitor brightness/picture settings over DDC/CI, HDR and display sleep timeout. Explicit sleep/shutdown timers can also change the machine power state.
Three places, all local and all by design. If you find a way to reach them from outside the machine, that is a vulnerability and worth reporting:
settings.jsonis read from the tool's own folder and is expected to be yours. It is parsed defensively — damaged JSON and nonsense values fall back to defaults rather than stopping the tool — but it is not a security boundary.- Commands before and after a switch, and rules, run programs you name in the
settings. That is the whole point of the feature:
hookslaunch whatever you put there, throughcmdorpowershelldepending on the extension. Anyone who can write to yoursettings.jsoncan already run code as you. native-*.dllis compiled on your machine from C# embedded inDisplayCore.ps1, cached next to the scripts, and named after a hash of that source. It is unsigned, so Smart App Control may refuse to load it; the tool then deletes it and compiles in memory instead. It is never downloaded.
- The scripts are unsigned, and running them needs an execution policy that
allows it. That is what the
.cmdwrappers pass-ExecutionPolicy Bypassfor, and it applies to the copy of the tool you already have on disk. hooksrunning a program you configured yourself.- Anything requiring an attacker who can already write into the tool's folder or run code as your user.