Please do not open a public issue for security reports.
Report privately through GitHub's private vulnerability reporting, or email security@labelzoom.com.
Please include enough to reproduce: affected repo and version, what an attacker can do, and a proof of concept if you have one.
We aim to acknowledge within 3 business days and to keep you updated as we work on a fix. If you would like credit in the advisory, say so and tell us how you would like to be named.
This policy covers the repositories in the labelzoom organization and the hosted service at labelzoom.com.
Findings that are generally out of scope: reports from automated scanners with no demonstrated impact, missing hardening headers with no exploit path, denial of service through sheer volume, and social engineering of LabelZoom staff or users.
Fixes land on the current release line. Older versions are patched only where a vulnerability is severe and the upgrade path is genuinely blocked.