Do not open a public issue for a suspected security vulnerability. Report it privately to the repository maintainers through GitHub's security advisory workflow, including reproduction steps and impact.
Security fixes are provided on a best-effort basis for the current 0.9 beta. The beta API is not a long-term-support release.