Until the first stable release, security fixes are applied to the latest published version only.
Please use GitHub private vulnerability reporting rather than opening a public issue. Do not include real access tokens, refresh tokens, API keys, account identifiers, or raw authenticated responses in a report.
Relevant reports include credential exposure, requests that can leave the official xAI origin, terminal or prompt injection through returned content, unbounded response handling, and authentication fallback that could cause unexpected billed usage.
You should receive an acknowledgement through the advisory within seven days.