kopsrox runs directly on a Proxmox VE host with root-equivalent API credentials, so a vulnerability here can have significant impact on the host and every guest it manages.
If you discover a security issue, please open a GitHub issue on this repository describing the problem. Avoid including exploit details or live credentials in the report — a maintainer will follow up to arrange a secure channel if needed.