Please do not disclose security vulnerabilities in a public issue. Use the repository's GitHub Security Advisory reporting flow so maintainers can triage and coordinate a fix before disclosure.
Do not include real credentials, access tokens, private repository content, or personal data in reports or reproduction fixtures. Revoke any credential that may already have been exposed.