Report a vulnerability through GitHub's private vulnerability form. Do not open a public issue for an exploit, exposed credential, unsafe installation path, or workflow permission problem.
Include the affected file or version, the smallest reproduction you can provide safely, and the impact you observed. The current main branch and the latest published plugin version are supported.
False positives in the catalog and ordinary plugin defects are not security reports. Use Discussions or the bug form for those.