Please do not disclose a suspected vulnerability in a public issue. Use GitHub's private vulnerability reporting for this repository.
Include the affected version, impact, reproduction steps, and any suggested mitigation. Do not include real credentials or sensitive source documents. No fixed response-time guarantee is currently offered; receipt and remediation status will be communicated through the private channel.
请不要在公开 Issue 中披露疑似漏洞。请使用本仓库的 GitHub 私密漏洞报告功能。
请说明受影响版本、潜在影响、复现步骤和可行的缓解方式,不要附上真实凭据或敏感来源文档。项目目前不承诺固定响应时限;确认收件和修复状态会通过私密渠道沟通。
Security reports may cover credential exposure, unsafe handling of untrusted documents or indexes, path traversal, destructive file operations, dependency or packaging risks, and unintended remote-provider data transmission.
安全报告可包括凭据泄露、不可信文档或索引处理、路径穿越、破坏性文件操作、依赖与打包风险,以及非预期的远程模型数据传输。