How to report a security issue in an open source project
      (jacobian.org)
So you’ve found a security issue in an open source project – or maybe just a weird problem that you think might be a security problem. What should you do next?
    
  So you’ve found a security issue in an open source project – or maybe just a weird problem that you think might be a security problem. What should you do next?