Report responsibly
Send security reports to [email protected] with a clear description, affected URL or component, safe reproduction steps, impact, and any proof of concept that does not expose personal data.
Safe testing
Do not disrupt the service, access accounts or infrastructure, exfiltrate data, run destructive tests, or publicly disclose an issue before allowing reasonable time for review and remediation. Stop immediately if you encounter sensitive data.
What happens next
We review the report, may request safe clarification, validate impact, and prioritize a fix according to severity and feasibility. Structured contact information is also available at /.well-known/security.txt.