Please do not publish exploit details for an unpatched vulnerability in a public issue. Report security concerns privately to the repository owner through GitHub's available private security-reporting channel when enabled. Avoid including secrets, proprietary datasets, credentials or personally identifiable data in reports or test fixtures.