This repository is a static website. It has no backend, no accounts, and no analytics: nothing you do here is collected.
A vulnerability in Milano itself belongs in get-milano/sdk, which is where the engines live, or in get-milano/specs when the defect is in the contract.
For problems with the site itself, report privately through this repository's Security tab, then Report a vulnerability. Please do not open a public issue for a suspected vulnerability.