Please report vulnerabilities through GitHub private vulnerability reporting when available. Do not post credentials, confidential source code, exploitable production details, or customer data in public issues.
Include the affected workflow, authority-boundary impact, reproduction conditions, and a minimal safe proof.