We appreciate your efforts to responsibly disclose your findings, and will make every effort to acknowledge your contributions.
To responsibly report a security issue, please navigate to the "Security" tab for the repo and click "Report a vulnerability".
Be sure to include as much detail as necessary in your report. As with reporting normal issues, a minimal reproducible example will help the maintainers address the issue faster.
Thank you.