Please do not disclose suspected vulnerabilities in public issues first. Use GitHub's private vulnerability-reporting or security-advisory flow for this repository when it is available.
Include a clear description, affected public page or feature, safe reproduction information, and the impact you observed. Do not include real student or user data, credentials, tokens, or secrets. Avoid destructive testing and do not access data that is not yours.
Public issues are appropriate for non-sensitive bugs only.