Do not report a vulnerability, exploit path, private RPC URL, token, seed phrase, or private key in a public issue.
Use GitHub's private security advisory form. Include the affected revision, impact, a minimal reproduction, and a safe contact method. The public coding factory deliberately holds every issue labeled security and never sends its body to an automated coding seat.