backend-web-real-time
Warn
Audited by Socket on Jul 8, 2026
1 alert found:
AnomalyAnomalyreferences/webrtc-architecture.md
LOWAnomalyLOW
references/webrtc-architecture.md
No explicit malware behaviors (backdoor/persistence/command execution/covert exfiltration to unrelated destinations) are evident in this fragment. The primary security concerns are (1) hardcoded/placeholder TURN credentials and coturn static-auth-secret (credential exposure risk if copied into real artifacts), and (2) lack of shown authentication/authorization for signaling room/targeting plus insufficient visible hardening for data-channel/file-transfer and SFU room forwarding. Overall, this is standard WebRTC architecture but could be high-impact for privacy and abuse if deployed without strong session authentication and peer trust controls.
Confidence: 64%Severity: 66%
Audit Metadata