Please report security vulnerabilities privately through GitHub's security advisory form for this repository. Do not open a public issue containing account credentials, verification codes, OAuth tokens, device serial numbers, or raw service responses.
Include the affected version, impact, and minimal reproduction details. You can expect an acknowledgement within seven days.