BedPad is a local remote-control tool. Anyone with the active URL and token can send keyboard and mouse input to the Windows session running the server.
- Trusted home LAN
- Short-lived local sessions
- Personal machines you control
- Public Wi-Fi
- Port forwarding
- Running without a token
- Sharing screenshots that include the full URL
Please open a private security advisory or contact the maintainer before publishing issues that allow bypassing the URL token or remote input without consent.