If you believe you have found a security vulnerability, please open a private security advisory via GitHub (Security tab -> "Report a vulnerability"). Provide as much detail as possible so we can reproduce and address the issue.
We will acknowledge receipt and provide a timeline for a fix when possible.