Please report (suspected) security vulnerabilities to [email protected]. Optional encryption keys are available at https://keybase.io/sublimino/pgp_keys.asc.
You will receive a response from us within 48 hours. If the issue is confirmed, we will release a patch as soon as possible depending on complexity, but historically within a few days.