Please do not report vulnerabilities in public issues. Use the repository's private security-advisory reporting channel when it is enabled, or contact the maintainers through the security contact published in the repository settings.
Include affected version, reproduction steps, impact, and any suggested mitigation. Do not include credentials or customer data.