Do not report vulnerabilities in a public issue, pull request, or discussion.
Email security@midfleet.ai with a minimal reproduction, affected surface, expected and observed behavior, and potential impact. Remove all credentials, customer information, private repository URLs, private addresses, and production payloads.
For public examples, include the example commit or release. For the hosted product, include only redacted workspace, project, run, and timestamp context needed to investigate.