Please do not open a public Issue for a vulnerability that could put users, data, or systems at risk.
Use GitHub's private vulnerability reporting feature on the affected repository when it is available. Include the affected version, impact, reproduction steps, and any suggested mitigation. If private reporting is unavailable, open a Discussion asking for a private security contact without publishing exploit details.
The maintainer will acknowledge a credible report, investigate it, and coordinate a fix and disclosure appropriate to the project's risk. Please allow reasonable time for that process before public disclosure.
Only the latest released version is guaranteed to receive security review. Feature-complete projects may receive security and critical correctness fixes without reopening their broader feature scope.