Security fixes target the latest commit on main and the latest published release.
Please use a private GitHub Security Advisory for the affected repository: open the repository's Security tab, choose Report a vulnerability, and include the affected version, reproduction steps, impact, and a suggested mitigation when available.
Do not post credentials, exploit details, or a vulnerability proof of concept in a public Issue or pull request.
We will acknowledge a report within seven days, investigate the impact, and coordinate a fix and disclosure timeline with the reporter.