Please report vulnerabilities privately through GitHub's private vulnerability reporting:
- Open the Security tab of this repository.
- Click Report a vulnerability.
Do not open a public issue containing a working exploit or sensitive details.
Remove everything sensitive before you submit: tokens, API keys, credentials, request headers, private absolute paths, and any real user memory content. Logs, error messages, and reproduction steps must contain only the minimum needed to reproduce the issue.
- Affected version(s)
- A short description of the issue
- Steps to reproduce (redacted)
- Expected vs. observed behavior
- Optional: a suggested fix
- First acknowledgement within 7 days (usually much faster).
- Status updates at least once every 14 days until resolution.
- After confirmation, the fix is published as a patch release and announced in the changelog.
- Coordinated disclosure: the report stays private until a fix is released.
- Reporters are credited (by name or handle, as they prefer) in the changelog and release notes unless they ask to remain anonymous.