Report a vulnerability privately to dev@bubo2.com, not in a public issue. Say what a page, a recording or a server can make the player do, which version or commit you looked at, and how to reproduce it. You get an acknowledgement within a few days and a fix, or an account of why it is not one, once we understand it.
Only the latest release is supported. The player runs in the visitor's browser and reads
recordings from the URLs a page gives it; docs/DEPLOYMENT.md says what the page and the
recordings' server must do, and the strict CSP the element runs under.