Do not open a public issue for an exploitable vulnerability. Use Report a vulnerability in the repository's Security tab.
Include:
- the affected version or commit;
- a minimal reproduction;
- the observed impact;
- any available remediation ideas.
The report will be acknowledged as soon as possible. Please wait until a fix is available before publishing technical details.
Parsing untrusted files, path resolution, file writes, and PDF generation are in scope. Purely visual defects without security impact should be reported as regular issues.