Don't report security vulnerabilities in public issues, pull requests, or discussions.
Report them privately through GitHub: open the repository's Security tab and choose Report a vulnerability. If the repository has no such button, email hello@anyone.no instead.
The principles in CONTRIBUTING.md apply here too: describe what you observed, give minimal steps you actually ran, and include raw output. Report what you verified; the maintainers will assess the impact.