Report security issues through GitHub private vulnerability reporting, at https://github.com/svyatov/oss-kit/security/advisories/new. It is enabled on this repository and it keeps the report private until there is a fix to disclose.
If the advisory form is unavailable, email leonid@svyatov.com instead. Do not open a public issue for a security report.
The maintainer acknowledges a report within one week of receiving it.