Please report vulnerabilities through GitHub Security Advisories or a private maintainer channel. Do not publish credentials, real media-server URLs, private video samples, or exploit details in public issues.
Reports should include the affected tag/commit, platform and target triple, a minimal reproduction, impact, and whether the issue involves the C ABI, prebuilt archives, native build scripts, Flutter glue, or network media handling.
Security fixes are prioritized for maintained release tags and the default branch. Locally rebuilt forks, unpinned prebuilt archives, and platform-preview paths may require separate validation.