QuickGrade processes student names, identifiers, answer sheets, and grades in the browser. Please do not publish a suspected vulnerability or real student data in a public issue.
Use GitHub's private vulnerability reporting form for this repository. Include the affected version or commit, reproduction steps using synthetic data, the expected impact, and any suggested mitigation.
If private vulnerability reporting is unavailable, open a public issue that contains no exploit details or student data and ask the maintainer for a private contact channel.
Security fixes target the current main branch and the hosted build generated
from it. Older downloaded copies should be replaced with a current build after
a security fix is published.