Report exploitable vulnerabilities privately to Piotr Olszewski. Include the affected version, a minimal reproduction, and the expected impact. Please allow time for a fix before publishing; the project has no fixed disclosure window.
Use GitHub issues for bugs that do not expose sensitive details or enable exploitation.
See deployment security for authentication, key permissions, and service hardening.