Please report security concerns through an approved private Start Small, Think Big contact channel. That contact method must be published before security reports can be accepted.
Do not disclose sensitive vulnerability details in a public issue, discussion, pull request, or comment.