Do not report suspected vulnerabilities in a public issue. Use the private contact options on the OpenCloud support page and include only the minimum reproduction details needed to investigate.
Never include passwords, OAuth tokens, cookies, database credentials, secret values, one-time links, or customer data in a report.