LineageRAG processes untrusted document text as data. The offline pipeline does not execute retrieved content, follow links, or make network requests.
Report a vulnerability through GitHub Security Advisories. Include a minimal reproduction and the affected version.
Do not submit sensitive data in a public issue.