Please use GitHub's Security tab and Report a vulnerability to submit security issues privately. Do not include credentials, private photos, personal filenames, or other sensitive user data in a public issue.
Include:
- affected version or commit;
- reproduction steps using non-sensitive sample data;
- expected and observed behavior;
- potential privacy, integrity, or availability impact; and
- a proposed mitigation, if known.
Security fixes target the latest version on the default branch.
Pay particular attention to path traversal, unintended network transmission, unsafe file handling, browser storage, user-controlled filenames, and accidental inclusion of private media in logs or repository history.