Please do not publish exploitable details in a public issue. Use GitHub's private vulnerability reporting or contact the repository owner through a private channel listed on their GitHub profile. Include affected versions or commits, impact, reproduction conditions, and a minimal proof of concept that does not expose third-party data.
This is an open engineering project, not a managed production service. Security support is best-effort. Dependencies, example credentials, hardware interfaces, uploaded files, imported datasets, and network endpoints should all be treated as untrusted boundaries.
Never include secrets, personal data, vehicle captures, industrial site details, or confidential evidence in a report. Coordinate disclosure so users have a reasonable opportunity to update.