Security fixes are provided for the latest released version. Please use GitHub's private Report a vulnerability feature instead of a public issue. Never attach API keys, private model data or unredacted diagnostics.
The public API binds to loopback by default. Users who expose it through a proxy or network interface are responsible for access control, TLS and firewall configuration.