If the issue is minor, just create a PR or an Issue on the repository.
If the issue is severe enough, email me at: oss-security-{YYYY} at ljoonal.xyz
But replace {YYYY} with the current year, if it wasn't obvious enough.
Please use a trustworthy email server to send your message from, and ensure it's using TLS.