Do not report security vulnerabilities through public GitHub issues.
Follow Retool's current vulnerability-reporting instructions at retool.com/vulnerability-reporting. Include the affected plugin and version, reproduction steps, and the security impact. Do not include customer credentials or production data.