If you believe you have found a security vulnerability, we would appreciate a private report so that we can work on and release a fix before public disclosure. Any vulnerabilities reported to us will be disclosed publicly either when a new version with fixes is released or 90 days has passed, whichever comes first.
Report the vulnerability through GitHub.