Please do not report suspected vulnerabilities through public GitHub issues.
Use GitHub's private vulnerability reporting with a description, affected versions, reproduction steps, and any proof of concept. GitHub makes this reporting channel available for public repositories; maintainers must enable it immediately after changing repository visibility and before announcing a release or accepting external reports.
We will acknowledge the report, investigate it, and coordinate disclosure with you before publishing a fix.