How to report a vulnerability without exposing users or sensitive details.
Security fixes are provided for the latest published minor version.
Report suspected vulnerabilities through GitHub private vulnerability reporting.
Do not open a public issue for a security vulnerability. Include only the minimum information needed to reproduce and assess the problem. Remove credentials, tokens, private URLs, customer data, and page contents.
The maintainers will review the report, confirm its scope, and coordinate a fix and disclosure when appropriate. Please allow time for an initial assessment before publishing details.
Reports about navigation policy bypasses, unsafe external targets, stale event handling, page-message trust, injected-script boundaries, or accidental publication of sensitive files are in scope.
The security of arbitrary third-party pages, consumer authentication systems, and consumer platform configuration remains the responsibility of the integrating application.