Security

Report vulnerabilities privately

Please avoid a public issue for a vulnerability or suspected data exposure. Use GitHub's private reporting channel so the impact can be investigated before disclosure.

Open a private security reportRead the full security policy

← Back to Site Behavior Lab

What to include

  • A concise description of the issue and the realistic impact.
  • Reproduction steps, including the affected route, input, or target when safe to share.
  • The affected report ID, deployment revision, or scanner version if known.
  • Any proof-of-concept data minimized to what is necessary to verify the issue.

High-priority areas

SSRF and network-boundary escapes, report data leakage, scanner resource exhaustion, authorization bypasses, and integrity failures in public evidence are especially important. The full repository policy documents the current safeguards and known platform boundary.

StatusCatalogMethodologyPrivacySecurityCorrectionsSource