Please report security concerns or vulnerabilities privately to security@workos.com. Do not open a public GitHub issue for a suspected vulnerability.
Include the affected action SHA, workflow context, and reproduction details when available. The WorkOS Security team will coordinate triage and remediation.