Please do not open GitHub issues or pull requests - this makes the problem immediately visible to everyone, including malicious actors. Security issues in this open source project can be safely reported to the developers through your contacts.
Any critical vulnerabilities can be reported to Amanda, Gustavo, Neemias and Ramon.