Report a vulnerability privately: on the repository's Security tab, choose "Report a vulnerability". That opens a private advisory visible only to the maintainers. Please do not open a public issue for a security problem.
Include what is affected, how to reproduce it, and the version (the footer of a running Studio shows it, as does /api/version). We acknowledge reports and fix confirmed issues in the next release, crediting the reporter unless they prefer otherwise.
Fixes land on main and ship in the next tagged release; older versions are not patched separately.