Please use GitHub's private vulnerability reporting to report security issues. Do not open a public issue for a suspected vulnerability.
We aim to acknowledge reports within 5 business days and will keep you informed as we work toward a fix. Security fixes are prioritised; critical issues are addressed as quickly as possible.