Please report a suspected vulnerability privately through GitHub's security advisory feature rather than a public issue. Include the affected version, operating system, reproduction steps, and expected impact when possible.
Read the Code processes adversarial repository names, filenames, patches, and comments. Security-sensitive changes should cover capability checks, loopback/Host/Origin restrictions, Git argument handling, path and symlink behavior, HTML injection, size limits, persistence races, or secret-free exports with regression tests.
The authenticated browser URL is a bearer capability. Do not include it in screenshots, issue reports, terminal transcripts, or exported review records.