Security fixes target the latest major release of each package. The current codebase targets Node.js 24 LTS and NestJS 12. Use the latest patch release within the supported major versions; older package majors do not receive guaranteed backports.
Email thilllon970@gmail.com. Do not open a public issue or pull request containing an undisclosed vulnerability.
Include the package and version, affected Node.js and NestJS versions, impact, and a minimal reproduction or proof of concept. Remove real credentials and customer data. If a patch is available, describe it in the report.
The maintainer will coordinate investigation, a fix, and disclosure with you. Avoid publishing exploit details until a fix or an agreed disclosure date is available.