Please do not open public issues for security vulnerabilities.
Instead, report vulnerabilities privately to the maintainer via email listed in src/_data/metadata.js (if configured), or through your repository host's private security advisory feature.
We will acknowledge reports as quickly as possible and provide updates during triage and remediation.