Microsoft takes the security of its software products and services seriously.
Do not report security vulnerabilities through public GitHub issues.
Report them to the Microsoft Security Response Center at https://aka.ms/security.md/msrc/create-report. If you prefer to submit without signing in, email secure@microsoft.com.
Include the issue type, affected source paths, reproduction steps, required configuration, impact, and a proof of concept when possible.
Microsoft follows Coordinated Vulnerability Disclosure.