Please do not disclose security-sensitive reports in a public issue. Use the repository's private security-advisory reporting flow and include the affected version, a minimal reproduction, and any relevant logs with secrets removed.
Supported versions are the latest commit on main and the latest npm release.