Security defects must not be reported through public GitHub issues.
Use GitHub Private Vulnerability Reporting for this repository when available.
Include enough information to reproduce and assess the issue, including:
- affected component and version;
- attack prerequisites;
- reproduction steps;
- expected and observed behavior;
- potential security impact.
Do not publicly disclose an unresolved vulnerability before coordinated disclosure.