Please report suspected vulnerabilities privately through GitHub Security Advisories. Do not open a public issue for a vulnerability before it has been triaged.
Include the affected SDK or CLI version, impact, reproduction steps, and a proof of concept when available. This policy covers the SDKs and CLI published from this repository. Reports about the hosted nvoken service can use the same private channel.