Report vulnerabilities privately through GitHub Security Advisories. Do not open a public issue for a suspected vulnerability.
ContextCrate processes untrusted remote content. Keep the default SSRF protections enabled, isolate browser workers, use non-administrator credentials, rotate the initial password, and expose the admin UI only through TLS.