Do not report vulnerabilities in a public issue. Use the repository's Security tab to submit a private vulnerability report.
Include the affected package version, impact, reproduction steps, and a minimal proof of concept without real credentials or user data.