Please report suspected vulnerabilities privately to security@yycore.ai. Do not open a public issue for a vulnerability before YY has had a reasonable opportunity to investigate it.
Include the affected version, reproduction steps, likely impact, and any known workaround. YY will acknowledge a complete report as capacity permits. This early-stage open-source project does not currently promise a fixed response or remediation SLA.