Do not open a public issue for a vulnerability that could expose database credentials, model-provider keys, private research profiles, or downloaded documents. Contact the maintainer privately through the security contact configured on the eventual public repository.
The local web interface deliberately binds only to 127.0.0.1 and has no authentication. Do not expose it through port forwarding, a reverse proxy, or a public network. Secrets belong only in the workspace .env file and must never be committed.