Please do not report security vulnerabilities through public GitHub issues.
Instead, use GitHub's private vulnerability reporting for this repository. Include as much of the following as you can:
- A description of the issue and its impact
- Steps to reproduce
- Affected components (
apps/api,apps/web,packages/widget, etc.)
You should receive a response within a few days. Please give us a reasonable window to ship a fix before any public disclosure.
- Widget API keys (
fbk_...) are public by design — they are embedded in script tags on third-party websites and only allow submitting feedback and reading the form config for that project. Exposure of a widget key is not a vulnerability by itself. - Reports about missing rate limits, auth bypasses on the dashboard, or cross-project data access are very much in scope.