Please do not open a public issue for a vulnerability. Report it privately through GitHub's security advisory feature. Include affected versions, reproduction steps, and impact. We aim to acknowledge reports within seven days.
Only the latest release receives security fixes. The local control socket binds to loopback and uses a randomly generated bearer token; never publish files from the application data directory.