Security fixes target the latest published Termatica release.
Do not include exploit details in a public issue. Use GitHub's private vulnerability reporting for this repository. Include affected versions, reproduction steps, impact, and any suggested mitigation.
Extensions are executable local programs and run with the current user's privileges. Termatica validates package paths and transport rules, but it does not sandbox installed extension code. Review source before installation and only use publishers you trust.