Please do not disclose suspected vulnerabilities in a public issue.
Use GitHub's private vulnerability reporting feature when it is available. Otherwise, contact the repository owner through the contact method listed on the GitHub profile and include:
- the affected file or component
- steps to reproduce the issue
- the potential impact
- any suggested remediation
Do not include active credentials, personal data, or exploit payloads beyond what is necessary to reproduce the issue.
The default branch is the supported version. Security fixes are applied there first.
Test only against systems and data you own or are explicitly authorized to assess.