Security fixes are applied to the latest release on the main branch.
Please use GitHub's private vulnerability reporting for this repository:
https://github.com/xraysight/aukctl/security/advisories/new
Do not include credentials, device serial numbers, real BLE addresses, account data, nearby-device data, or other private identifiers in a public issue.
aukctl is a local Bluetooth LE client. It does not open a network port or use an Auk cloud account. It intentionally exposes only tested, explicitly allowlisted operations and cannot send arbitrary GATT payloads.