Until JAP publishes tagged releases, security fixes target the latest revision of main.
Please do not open a public issue or discussion for a suspected vulnerability.
Use GitHub's private Report a vulnerability form in the Security tab of markos-ttl/JAP. Include the affected revision, impact, reproduction steps, and any suggested mitigation. Remove API keys, access tokens, generated images, prompts, and other personal data from logs or screenshots before attaching them.
If private vulnerability reporting is unavailable, contact the maintainer privately through the options listed at https://github.com/markos-ttl and mention only that you need a secure reporting channel.
You can expect an initial acknowledgment within seven days. Please allow time for a fix before publishing details.
As of 2026-08-02, react-router-dom@7.18.2 is covered by
GHSA-qwww-vcr4-c8h2.
The advisory affects only React Router's unstable React Server Components APIs.
JAP is a client-rendered Vite application using BrowserRouter; it does not use
React Server Components, server actions, or React Router's RSC request handlers.
The advisory is therefore not reachable in JAP. The first patched version named
by the advisory (8.3.0) is not currently obtainable from npm; this assessment
will be revisited when an installable patched release is available.