Do not file public issues for vulnerabilities.
Report them with GitHub private vulnerability reporting. If that is unavailable, email rohan@surfsense.com (same address as CODE_OF_CONDUCT.md).
Include the tree (surfsense_local, surfsense_backend, surfsense_web, surfsense_mcp), a reproduction, and impact.
We will acknowledge the report and fix before any public disclosure.