Build198x is deferred and not yet built, so there is no shipping code to attack today. When it exists it will be a front-end that drives other tools (Asm198x, Emu198x), so the realistic risks will be around how it handles untrusted projects and the inputs it passes through, rather than remote compromise. Reports are welcome regardless.
Please report suspected vulnerabilities privately to steve@stevehill.xyz rather than opening a public issue. Include the steps to reproduce.
This is a small project without a formal response window, but reports are read and acted on. Once a fix ships, credit is given gladly — unless you'd rather stay anonymous.