Report path traversal, command execution, archive extraction, approval bypass, executable-hash bypass, plugin corruption, or unsafe live-data writes privately through GitHub vulnerability reporting when available.
Include the Forge version, operating system, exact typed job, sanitized configuration, expected boundary, actual behavior, and a minimal reproduction with no copyrighted game assets.