Please do not open a public issue for a security problem.
Use GitHub's private vulnerability reporting instead: go to the Security tab of this repository and choose Report a vulnerability. That opens a private channel visible only to the maintainer, and it lets the report be tracked and credited properly once it is fixed.
Useful things to include, if you have them:
- what an attacker can do, and what they need in order to do it
- the steps to reproduce, or a minimal proof of concept
- the version, commit, or environment where you observed it
This is a maintainer-hours project, not a funded programme — there is no response-time guarantee, and it would be dishonest to print one. Reports are read, and confirmed issues are fixed and disclosed once a fix exists.
Anything in this repository. Findings in a third-party dependency should go to that project; if the dependency is reachable through this one in a way that makes the problem worse, it is worth reporting here too.