Please do not open a public issue. Use GitHub's private vulnerability reporting and include steps to reproduce. Expect an initial response within a week.
This is a starter template: it ships without authentication and with demo data.
Before deploying anything built from it, add auth, set CORS_ORIGIN to your real
origin, and review src/server/middleware/security.js.