Please report suspected vulnerabilities through GitHub private vulnerability reporting. Do not include credentials, tokens, or exploit details in a public issue.
Security fixes are supported on the latest released version. Reports should include the affected version, impact, reproduction steps, and any suggested mitigation. You can expect an initial acknowledgement before public disclosure.