Please report security vulnerabilities privately through GitHub Security Advisories.
Do not open a public issue for a vulnerability before the maintainer has had an opportunity to investigate and release a fix.
Include a description, reproduction steps, expected impact, affected versions, and any suggested mitigation.