Report vulnerabilities privately through GitHub Security Advisories for
openhoo/hoovda.
The control API must bind to loopback, require a high-entropy bearer token, bound request and artifact sizes, reject path traversal, and never expose environment variables or browser profile contents.