Please do not report security vulnerabilities in public issues. Send a private report to the repository maintainers with a description, reproduction steps, and the affected commit or version. Do not include database files, encryption keys, or other private data in the report.
We will acknowledge reports as soon as practical, investigate them, and coordinate a fix and disclosure timeline with the reporter.