Do not open a public issue for vulnerabilities that could affect the live service or player data.
Contact the project owner privately with a description, reproduction steps and the affected component. Do not include real credentials, tokens, account exports or player data in reports.
Supported security fixes target the current main branch.