Please do not disclose security vulnerabilities in public issues. Report them privately through GitHub Security Advisories for this repository. Include affected versions, reproduction steps and the expected impact. Credentials, database files and production data must never be attached.