Please report suspected security vulnerabilities privately through GitHub's security advisory flow for this repository. Do not open a public issue for a vulnerability before a fix is available.
Do not include live verification tokens, customer exports, credentials, or other sensitive data in a report. Verification tokens are redacted by design; changes that weaken that behavior should be treated as security-sensitive.