Use GitHub's private vulnerability reporting for this repository. Do not open a public issue or include exploit details in a public pull request.
Include the affected route or component, reproduction steps, expected impact and any suggested mitigation. Remove credentials, personal data and customer information from evidence.
Security reports are particularly important for:
- Authentication, sessions and password recovery.
- Supabase RLS, storage policies and privileged RPCs.
- Service-role or integration credential exposure.
- AI credit billing and reservation settlement.
- Cross-user show, media or import access.
- Internal render and worker authentication.
The current main branch is the supported version. Historical branches and
local development configurations are not maintained security releases.