Please do not publish a security issue in a public issue tracker before a maintainer has had a chance to assess it. Use GitHub's private security-advisory feature, or email eddie.pohjavirta@gmail.com.
Reports should include the MaxView version, operating system, a minimal sanitized reproduction, and any security impact you observed. Do not include credentials, raw private transcripts, or other sensitive artifacts.