Report a vulnerability privately at https://github.com/Aitherium/awdesk/security/advisories/new (preferred) or by email to security@aitherium.com — never as a public issue. The full policy, scope and response commitment are in the organisation policy: https://github.com/Aitherium/.github/blob/main/SECURITY.md