Please use GitHub's private vulnerability reporting feature for this repository. Do not open a public issue containing credentials, personal data, private infrastructure details, or working exploit instructions.
Include:
- The affected version or commit.
- The impacted endpoint or component.
- Reproduction steps using non-sensitive test data.
- The expected security impact.
- Any suggested mitigation, if available.
Rotate any credential before including related logs or configuration excerpts. Remove tokens, passwords, database URLs, private domains, and client data from attachments.
Security fixes currently target the latest commit on the main branch.