Please do not report security vulnerabilities through public GitHub issues.
Report them privately, through either channel:
- GitHub Private Vulnerability Reporting for this repository, from its Security tab, when available;
- email to security@kaiten.sh, which also suits reporters without a GitHub account.
Include, where possible:
- affected version or commit;
- vulnerability description;
- reproduction steps or proof of concept;
- expected impact;
- known mitigations.
KAITEN INC asks reporters to allow reasonable time to investigate and address a vulnerability before public disclosure.