Please do not open a public issue for a suspected vulnerability.
Email info@hollyhr.com with the subject HollyHR security report. Include the affected repository or URL, the impact you observed and concise reproduction steps. Do not include real employee records, credentials or other sensitive data.
We will acknowledge a useful report and coordinate next steps privately.