Babylon captures application network traffic and must only be enabled in debug builds.
Security fixes are applied to the latest release and the current main branch. Older versions may receive a migration recommendation instead of a patch.
Do not open a public issue for a vulnerability that could expose captured traffic, affect host-app networking, bypass receiver authentication, or crash an application using Babylon.
Report the issue privately through the Security tab of the Babylon GitHub repository. Include the affected version, platform, reproduction steps, impact, and a minimal proof of concept.
Do not include real credentials, cookies, request bodies, device names, project identifiers, pairing tokens, or other captured data. Use synthetic fixtures and redact crash logs before attaching them.
- Babylon does not install certificates or change system proxy settings.
- Automatic capture and runtime hooks are active only after
Babylon.start()in aDEBUGbuild. - A start call without a pairing token is delegate-only and does not open local-network transport.
- Network delivery requires a 64-character lowercase hexadecimal token generated by Rockxy.
- Each frame is authenticated and encrypted with AES-256-GCM using a per-session HKDF-SHA256 key.
- Captured traffic is held in bounded memory and is not written to local storage by Babylon.
- Common authentication headers, cookies, and token query items are redacted before delegate or network delivery.
- Pairing tokens are secrets and must not be committed, logged, placed in production configuration, or included in diagnostics.
- Vulnerabilities that require a modified host application to deliberately expose its own captured packages.
- Findings against unsupported versions without a reproduction on the latest release.
- Reports containing only automated scanner output without a reachable code path or security impact.
For deployment boundaries and residual risks, read Security and privacy.