Do not open a public issue. Use Report a vulnerability in the repository's Security tab so the report and any fix can be discussed privately.
Include the affected component, practical impact, reproduction steps, and any suggested mitigation you already have. Relevant reports include catalog-input validation bypasses, unsafe remote fetching, workflow credential exposure, provenance or integrity bypasses, unsafe generated content, and vulnerabilities in the deployed website.
A vulnerability in an upstream application is normally best reported to that application. Report it to AppHub when AppHub misrepresents the application, bypasses its own validation, or exposes users or infrastructure to additional risk.