Do not open a public issue for a security vulnerability. Report privately to the security contact:
Preferred: this repository's private security advisory. Open the Security tab and click "Report a vulnerability", or go straight to https://github.com/npci/ainxt-os/security/advisories/new. The report stays confidential between you and the maintainers until a fix is published, and GitHub handles CVE assignment if one is warranted.
By email: opensource@npci.org.in — the NPCI Open Source Programme, a monitored
group address rather than an individual mailbox. Use this if you cannot or prefer not
to use GitHub. For sensitive reports the GitHub advisory is still preferred, because it
keeps the disclosure timeline and the fix in one auditable place.
Please include: affected component/version, a description, reproduction steps or PoC, and impact. We follow coordinated disclosure.