Please report suspected security vulnerabilities to security@glints.com. If the issue is confirmed, we will release a patch as soon as possible depending on complexity, but normally within a few days.
For more details, we have a public bug bounty @ https://security.glints.com