Do not report security vulnerabilities in public GitHub issues.
Use GitHub's private security reporting features for this repository when available.
Include the affected version, a clear description, a minimal reproduction when safe, and potential impact.
Never include passwords, API keys, access tokens, or other secrets.