Please report security issues privately through the Security tab of the affected repository by opening a private vulnerability report. Do not disclose an unpatched vulnerability in a public issue.
Include the affected version, operating system, reproduction steps, observed impact, and any suggested mitigation. Never attach live credentials, private model data, or identifying machine information.