Do not open a public issue for a suspected vulnerability or include credentials, tokens, cookies, or unredacted logs in any report.
Use GitHub's private vulnerability reporting for this repository:
- Open the repository's Security tab.
- Choose Advisories and Report a vulnerability.
- Include affected versions, impact, minimal reproduction steps, and a proposed mitigation when available.
If private vulnerability reporting is unavailable, open a public issue containing only a request for a private maintainer contact. Do not include technical exploit details in that issue.
Security fixes are made against the latest release. Reproduce the issue on the latest version before reporting when it is safe to do so.