Report vulnerabilities privately through GitHub Security Advisories. Filenames can contain private information; sanitize examples before posting. Path traversal, output safety, unintended file access, and dependency concerns are in scope. The current release receives security fixes.