Do not open a public issue for a vulnerability that could expose health data, bypass review, weaken result disclosure controls, escape a container, or reach a private service.
Use GitHub's Report a vulnerability action on this repository. Include the affected commit, proposal ID, impact, and a minimal synthetic-data reproduction. Do not include participant data, credentials, private endpoints, or production logs.
The maintainers will acknowledge the report, reproduce it on generated data, and coordinate a fix before public disclosure. There is no bug-bounty promise.
The public repository is not a production security boundary. Production image scanning, runtime network isolation, resource limits, approved-image binding, dataset access, and result-policy enforcement must be verified separately by the operator.