Report vulnerabilities privately through GitHub Security Advisories.
Include the affected contract and version, chain and address when applicable, impact, reproduction steps, and any proposed mitigation. Do not open a public issue for an undisclosed vulnerability.