Please report vulnerabilities privately via GitHub's private vulnerability reporting rather than in a public issue. We aim to acknowledge reports within five working days.
Do not include real client secrets, tokens, tenant names or customer data in a report.