Security fixes are applied to the latest code on the main branch.
Please do not disclose suspected vulnerabilities in a public issue. Use GitHub's private vulnerability reporting option on the repository's Security tab. If that option is unavailable, contact the maintainer through the GitHub profile before sharing sensitive details.
Include the affected component, impact, reproduction steps, and any suggested mitigation. Do not include real uploaded documents, database files, local configuration, credentials, or other private data. You should receive an acknowledgement within seven days.