Please use GitHub private vulnerability reporting. Do not open a public issue with exploit details, credentials, private data, or an unpatched proof of concept.
If private reporting is unavailable, email giodl73@gmail.com with the
repository name and a concise impact summary.
Security fixes target the default branch. Reports should identify the affected parser, path, network operation, generated artifact, dependency boundary, or evidence-integrity contract.