Please do not disclose suspected vulnerabilities in a public GitHub issue.
Use private vulnerability reporting where it is enabled for the affected repository. Otherwise, contact the maintainer using the contact information on the xnoto GitHub profile and include the affected repository, a clear description, reproduction steps, and potential impact.
This default policy may be overridden by a repository-specific security policy.