Please do not disclose a suspected vulnerability in a public issue.
Use the repository's private vulnerability reporting flow under the Security tab when it is enabled. If that private flow is unavailable, contact the repository owner through a private channel listed on their profile before sharing technical details.
Reports should include the affected version, a minimal reproduction, impact, and whether untrusted input can trigger the issue under Equatorium's published request limits.