Please do not open a public issue for a vulnerability.
Report it privately to jacobk2112@gmail.com. Include the affected commit or version, impact, and the smallest synthetic reproduction you can provide. Never send OAuth tokens, client JSON, real email, attachments, or account cookies.
Security fixes are made on main and included in the next release. Only the latest release is supported once public releases begin.
For the data boundary and threat model, see docs/security.md.