Please do not disclose security vulnerabilities in a public issue. Use GitHub’s private vulnerability reporting when available, or contact the repository owner privately through GitHub.
Include:
- the affected version
- a minimal reproduction
- the impact you observed
- any suggested mitigation
Please allow time for investigation before publicly disclosing the issue.