Report vulnerabilities privately through this repository's GitHub security advisory interface when enabled, or email open-source-team@scitrera.com. Include the component/version, configuration, reproduction steps, and impact. Avoid publishing credentials or tenant data in issue reports.