Please report suspected vulnerabilities privately using GitHub's Report a vulnerability form. Include a minimal reproduction, affected versions, and the potential impact; remove API keys, prompts, and other private data from examples.
Do not open a public issue for an unpatched vulnerability. Maintainers will coordinate disclosure and a fix through the security advisory.
The currently supported release is the latest npm version. Older versions may not receive fixes; upgrade to the latest release when one is available.