Please report potential security vulnerabilities through OpenAI's coordinated vulnerability disclosure process. For questions about that process, contact disclosure@openai.com.
Do not report vulnerabilities through public GitHub issues, discussions, pull requests, or other public channels. When reporting privately, include the affected SDK version, impact, and reproduction steps where possible; redact API keys, authentication headers, private keys, and customer data from all reports.
Please allow OpenAI a reasonable amount of time to investigate and address the issue before making information public. Thank you for helping us keep this SDK and the systems it interacts with secure.