Security fixes target the latest main branch and, when practical, the latest
published release.
Please use GitHub's private vulnerability-reporting flow from the repository's Security tab. If that option is unavailable, open a minimal public issue asking the maintainer to establish a private channel; do not include exploit details.
Do not attach credentials, personal or property-level records, proprietary files, or other sensitive material. Describe the affected component, expected impact, reproduction conditions, and a possible mitigation if known.