Use GitHub's private vulnerability reporting for this repository. Do not open a public issue for a suspected vulnerability.
Include the affected version, operating system, a minimal reproduction, and the expected security impact. Remove credentials, instance addresses, host names, user data, and full logs before submitting the report.
Baize MCP must not print, log, or return login passwords or session credentials. If a credential may have been exposed, revoke the affected Baize session and replace the credential before sharing diagnostic information.