Public route, form endpoint, generated asset, header, redirect, or security.txt path.
requiredExact request, browser behavior, payload, screenshots, and minimum steps needed to confirm the issue.
requiredWhat data, integrity, availability, or trust boundary could be affected if exploited.
requiredEmail or preferred contact method for follow-up and coordinated resolution.
optional