Do not open a public issue for a suspected vulnerability. Use GitHub's private
security advisory feature for this repository or contact SECURITY_CONTACT.
Include affected versions, reproduction details, potential impact, and any known mitigation. Maintainers should acknowledge a report within five business days and coordinate disclosure after a fix is available.
Replace the contact and response expectations before publishing the repository.