Please use https://github.com/warrenwoodhouse/forums/labels/codes to report security vulnerabilities.
I use https://github.com/warrenwoodhouse/forums/labels/codes for my intake and triage. For valid issues I will do coordination and disclosure here on GitHub (including using a GitHub Security Advisory when necessary).
I will process your report within a day and respond within a week (although it will depend on the severity of your report).