Security fixes are provided for the latest published Windows release and the currently deployed cloud demo.
Please use the repository's private Security advisory form. Do not open a public issue for suspected credential exposure, SSRF, authentication bypass, arbitrary file access, or remote code execution.
Include the affected version, reproduction steps, impact, and a minimal proof of concept. Do not include real user content, cookies, tokens, or credentials.
We will acknowledge a valid report, investigate it privately, and coordinate a release before public disclosure. There is no authorization to access data or accounts that you do not own, bypass platform verification, or disrupt the service while testing.