Do not report suspected vulnerabilities or exploitable details publicly.
Use the affected repository's Security tab and choose Report a vulnerability to open a private GitHub security advisory. For Kaimahi, use:
https://github.com/kaimahi-agents/kaimahi/security/advisories/new
Include the affected commit or version, deployment assumptions, reproduction steps, impact, and any suggested mitigation. Remove credentials, tenant identifiers, cluster addresses, and user data.
Kaimahi is an incubation project with no formal support window or response-time SLA. Maintainers will acknowledge actionable reports and coordinate disclosure through the private advisory.