Security
Send a vulnerability report through GitHub's private advisory form.
Report An Issue
Include the affected URL, the impact, steps to reproduce, and a minimal proof. Remove credentials and personal data from the report.
Safe Handling
Use test data and the smallest request that proves the issue. Avoid service disruption, access to other people's data, persistence, social engineering, and public disclosure before a fix is ready.
What Happens Next
The report receives a private review. Confirmed issues stay on the public-release closure ledger until a regression test and deployment check pass.