Security fixes are applied to the latest release on the main branch.
Please do not open a public issue for a suspected vulnerability.
Use GitHub's Security tab and choose Report a vulnerability to send a private report to the maintainers. Include reproduction steps, affected browser and version, impact, and any suggested mitigation. Remove proprietary harness data, credentials, and personal information from attachments.
The maintainers will acknowledge a report as soon as practical, investigate it, and coordinate disclosure after a fix is available. If private vulnerability reporting has not yet been enabled for the repository, contact Garth Benson privately through the contact information on his GitHub profile.
WireForm runs locally in the browser and does not intentionally transmit harness data. Reports involving dependency supply-chain integrity, unsafe SVG handling, vendored WebAssembly, component-library imports, or generated downloads are within scope.