If you discover a vulnerability, please open a private security advisory on GitHub (Security > Advisories), or email security@example.com. Do not open a public issue for security reports.
We will acknowledge and address reports as quickly as possible.