Please do not open GitHub issues or pull requests - this makes the problem immediately visible to everyone, including malicious actors. Security issues in this open source project can be safely reported via email ([email protected]).
Thanks for helping make GitHub safe for everyone.