Please do not report security vulnerabilities in a public issue, proposal or pull request.
Report them privately to Alex Springer at alex@spurcoalition.org. Include the affected component or specification section, the potential impact and enough detail to reproduce or assess the problem. Please avoid including personal data, credentials or other secrets unless they are necessary to understand the report.
We will acknowledge the report and coordinate disclosure and remediation with you before publishing details.