Please do not report vulnerabilities in public issues.
Use GitHub's private vulnerability reporting: open the affected repository, then Security → Report a vulnerability. If that is not possible, write to us through the Krizaka contact form without technical details, and we will open a private channel.
We acknowledge reports within two business days, keep you informed while we fix, and credit you in
the advisory unless you prefer otherwise. Supported versions: the latest release and main.