Please do not open a public issue for vulnerabilities involving credential exposure, approval bypasses, session confusion, path containment, or unintended external data transmission.
Report them privately through GitHub's Security → Report a vulnerability feature for this repository.
Include the affected version, reproduction steps, expected behavior, and the smallest non-sensitive evidence needed to investigate.
Never attach API keys, browser profiles, cookies, .env files, private keys,
customer data, or regulated data to an issue or pull request.