Please report suspected vulnerabilities privately to [email protected], with Security report and the affected project in the subject. Include a concise description, affected version and safe reproduction steps.
Do not post credentials, customer data or vulnerability details in public issues. If the repository has its own security policy, follow that policy instead.