Please do not open a public issue for anything security-sensitive.
Instead, use GitHub's private vulnerability reporting: open the Security tab of this repository and click Report a vulnerability. Your report stays visible only to the maintainers until a fix is released.
This repository holds community plugins. If the problem is in a plugin in this library (for example, a plugin that mishandles credentials or exposes data it should not), report it here. If the problem is in the OpenAVC platform itself, report it privately in the openavc repository instead.
Include what you found, how to reproduce it, and which plugin and version is affected. We will respond as quickly as we can, and we are happy to credit you for the find if you want.