Do not open a public issue for a suspected vulnerability. Use GitHub's private security advisory flow for this repository:
https://github.com/holon-technologies/karteros/security/advisories/new
Include the affected revision, impact, reproduction steps, and any suggested mitigation. Do not include real credentials, private user data, or production system details.
Karteros is experimental and has not published a stable release. Security fixes apply to the latest revision and to explicitly identified release lines. Git consumers should pin immutable tags or commits and review upgrades.