Microsoft takes the security of PyRIT seriously.
If you believe you have found a security vulnerability, do not report it through a public GitHub issue. Submit it privately to the Microsoft Security Response Center. The repository’s security policy describes alternative reporting methods, the information to include, and Microsoft’s coordinated vulnerability disclosure policy.
Review the PyRIT release notes for customer-facing security notices, known high-priority security issues, breaking changes, and compatibility guidance for each release.