Please do not report security vulnerabilities in public issues.
Use the affected repository's Security tab and choose Report a vulnerability to send details privately. If private vulnerability reporting is unavailable, email info@columbus-labs.com with the repository name and a concise description of the issue.
Include reproduction steps, affected versions, potential impact, and any suggested mitigation you have identified. We will acknowledge a complete report as soon as practical and coordinate remediation and disclosure with the reporter.