Playtestr executes trusted local targets with the user's permissions. A PTY, subprocess, container, or test fixture is not a security sandbox.
Report a suspected vulnerability through GitHub's private vulnerability reporting form. Do not include secrets or exploit details in a public issue. Include the affected Playtestr version, host, impact, and the smallest sanitized reproduction you can provide. The repository owner reviews these reports, but no response-time or long-term support SLA is promised.
General bugs that contain no sensitive material belong in the public bug-report form.