Please do not report vulnerabilities, exposed credentials or private-data leaks through a public issue.
Describe:
- the affected repository and version or commit;
- the security boundary that can be bypassed;
- the smallest safe reproduction;
- the potential impact;
- whether credentials, private images, prompts, datasets or generated artefacts may have been exposed.
Do not attach real secrets or private user content. Use redacted samples whenever possible.
Repository-specific security policies take precedence over this default policy. Experimental and source-available projects may have narrower support guarantees, but credible reports about secret exposure, unsafe file access, command execution, path traversal, origin validation or private-data disclosure are still relevant.
For a private report, use the repository owner's contact channel listed on the associated product or organization profile rather than opening a public issue.