Please do not report security vulnerabilities through public GitHub issues.
Email security@openleash.com with:
- a description of the issue and its impact;
- reproducible steps or a minimal proof of concept;
- affected versions or deployment configurations; and
- any mitigations you have already identified.
Do not include live credentials, administrative tokens, provider data, or customer event contents. OpenLeash will acknowledge the report and coordinate disclosure after a fix is available.