Please report vulnerabilities privately through the repository's Security → Report a vulnerability flow. Do not open a public issue containing webhook credentials, GitHub tokens, private keys, OAuth codes, or tenant data.
Include the affected route or component, the impact, and a minimal reproduction with all credentials replaced. The maintainers will acknowledge the report, investigate it, and coordinate disclosure after a fix is available.
Only the latest commit on main is supported during the initial development phase.