Security Report vulnerabilities privately to peter@zenjoy.be. Please do not open a public issue for a security bug until we have a fix, or we say otherwise. GitHub private vulnerability reporting is fine once the repository is public.