Do not open a public issue for an exploitable vulnerability or include tokens, cookies, credentials, private URLs, or personal data in a report.
Use GitHub's private vulnerability reporting feature when enabled. Otherwise,
contact the maintainer through the address in package.json with the minimum
reproducible details needed for triage.
Relevant reports include unsafe browser navigation or evaluation, credential or header leakage, remote code execution, dependency vulnerabilities affecting runtime behavior, and accidental disclosure of private data. Test only systems you own or are authorized to assess.