# Security ## Reporting a vulnerability Please report security issues privately via GitHub Security Advisories (the repo's **Security → Report a vulnerability** tab) rather than a public issue. We aim to acknowledge within a few days. Until `1.0.0` the project is a preview; fixes ship under the `next` dist-tag. ## Threat model `@crafted-design/editor` is a **client-side** editor. It collects nothing and ships no analytics. Documents are JSON, rendered live by the chosen adapter. The security-relevant surfaces are the few places user-supplied strings reach CSS or URLs. ### Validated injection surfaces (Phase 15 § 11.2) The editor injects runtime `