Please file a private vulnerability report,or email @ljharb,if you have a potential security vulnerability to report.
See our Incident Response Process.
See THREAT_MODEL.md.