Do not disclose a suspected vulnerability in a public issue.
Email liuzaoqu@163.com with the subject [πAI Security] and include:
- affected repository and version or commit;
- impact and realistic attack scenario;
- reproduction steps or proof of concept;
- known mitigations;
- whether the issue has been shared elsewhere.
We will acknowledge reports as capacity permits, coordinate validation with the relevant maintainer, and agree on a disclosure plan when the report is confirmed. Please avoid accessing data that is not yours, degrading services, or expanding testing beyond what is necessary to demonstrate the issue.
Each repository defines its own supported versions. If no support table is present, only the latest release or default branch should be assumed in scope.
Security fixes do not establish scientific, clinical, or regulatory validity. Those claims require separate evidence.