Hi maintainer,
I found several potential security issues and would like to report them responsibly. I could not find a security contact or private disclosure channel, so I am opening this public issue without technical details.
At a high level, they are similar to common cases such as:
- unsafe default credentials or development defaults
- weak credential-handling assumptions
- production deployments exposing sensitive functionality
For ethical reasons, I will not publicly share affected files, endpoints, credentials, PoC code, or reproduction steps in this issue for now.
Could you please provide a security contact email so I can report the details privately?
Thank you.
Hi maintainer,
I found several potential security issues and would like to report them responsibly. I could not find a security contact or private disclosure channel, so I am opening this public issue without technical details.
At a high level, they are similar to common cases such as:
For ethical reasons, I will not publicly share affected files, endpoints, credentials, PoC code, or reproduction steps in this issue for now.
Could you please provide a security contact email so I can report the details privately?
Thank you.