Do not file a public issue for a vulnerability that could expose a Clash Controller secret, broaden controller access beyond loopback, or cause the app to close an unverified connection.
Use GitHub's Report a vulnerability flow when it is enabled for this repository. If it is unavailable, contact the repository owner through their GitHub profile and include only redacted reproduction details. Do not send Controller secrets, raw connection IDs, or full game logs.
- Controller requests are restricted to loopback HTTP endpoints with an explicit port.
- The optional Controller secret is stored in macOS Keychain and must never be committed or attached to an issue.
- The app must refuse an action when it cannot prove one stable game-server connection.
This project is not affiliated with Blizzard Entertainment.