Report a vulnerability through GitHub: Security tab, then Report a vulnerability. That's private, only the maintainer sees it. Please don't open a public issue for it.
Expect a first reply within a week. There's no bounty, this is a hobby project.
Only the latest release gets fixes. Older versions are not patched.
Useful context if you're looking at it:
- Runs as a normal user process. No service, no driver, no elevation.
- Installs a low-level mouse hook (
WH_MOUSE_LL) when taskbar gestures are on. It reads wheel and middle-click events to find the taskbar button under the cursor. It's not a keylogger, and it can be turned off in settings. - Registers global hotkeys through
RegisterHotKey. - Reads the Windows media session (SMTC) for track info, and Core Audio for volume.
- Writes
lumen.config.jsonandlumen.stats.jsonnext to the exe, or in%APPDATA%\Lumen\if that folder is read-only. Optionally writes now-playing files for OBS to a folder you choose. - Writes one registry value under
HKCU\Software\Microsoft\Windows\CurrentVersion\Runif you turn on "Start with Windows".
Network requests, all off by default and all over HTTPS with WinHTTP:
| Feature | Goes to | Sends |
|---|---|---|
| Lyrics | lrclib.net, genius.com | artist, title, album, duration |
| Discord cover art | itunes.apple.com | artist, title |
| Update check | raw.githubusercontent.com | nothing, it reads a version file |
Discord Rich Presence talks to the local Discord named pipe. No analytics, no telemetry, no account, and the exe never updates itself.