If you discover a potential security issue in this project, please notify the security team through the security center or the vulnerability reporting email listed there. Please do not create a public GitHub Issue.
We will assess the vulnerability based on the Common Vulnerability Scoring System (CVSS 3.1). The security team will keep you updated on key progress and may request further information or guidance from you. You are welcome to contact us via the email or website mentioned above to ask questions or discuss disclosure matters.
To protect users, do not publish or share vulnerability details or user data in any public forum until the issue has been remediated and affected users have been notified.
Please contact the security team before publishing an advisory so that the disclosure scope and timeline can be coordinated.