Security fixes are applied to the latest release and the current main branch. Older versions may not receive fixes.
Please do not publish sensitive vulnerability details in a public issue.
Use GitHub's private vulnerability reporting option from the repository's Security tab when it is available. If private reporting is unavailable, open a minimal issue asking the maintainer for a private contact method without including exploit details, credentials, private phrases, or other sensitive information.
Include the affected version, impact, reproduction conditions, and any suggested mitigation in the private report.