Please report security issues privately through the repository's GitHub Security Advisory interface. Do not open a public issue containing an undisclosed vulnerability.
Snapshot and Inspector inputs are untrusted data. Reports involving parser, validator, resource-exhaustion, or DOM-injection behavior are in scope.