Do not publish exploit details, session cookies, credentials or other users' files in public issues.
Use the repository's Security → Advisories → Report a vulnerability option if the owner has enabled private vulnerability reporting. If that option is unavailable, ask the maintainer to provide a private reporting channel without posting vulnerability details. No security contact or response-time commitment has been configured in this repository yet.
Include the affected commit, deployment setup, impact and minimal reproduction using synthetic files. Share sensitive details only through the agreed private channel.
Не публикуйте описание эксплуатации уязвимости, cookie, пароли или чужие файлы в открытых issues. Если владелец включил приватные отчёты, используйте Security → Advisories → Report a vulnerability. Если такой кнопки нет, запросите у владельца закрытый канал связи без подробностей уязвимости. Контакт для безопасности и срок ответа пока не заданы.
Укажите коммит, способ установки, последствия и минимальный пример на искусственных файлах. Подробности передавайте только через согласованный закрытый канал.