Please report vulnerabilities privately by contacting the maintainer via LinkedIn (https://www.linkedin.com/in/arafmustavi/). Do not open a public issue.
- Auth bypass on the dashboard.
- Prompt-injection leading to CSV corruption.
- Container escape / dependency CVEs.