Please do not publish exploitable vulnerabilities before a fix is available.
Open a private GitHub security advisory for the repository and include:
- affected version or commit;
- operating system and architecture;
- minimal reproduction;
- security impact;
- suggested mitigation, when known.
BeforeRun intentionally reads untrusted repository contents. Reports should never print full suspected credential values. New parsers and detection rules must remain non-executing and should be tested against malformed input.