Please do not open a public issue for a vulnerability in any eQuantic repository. Use GitHub's private reporting instead: Security → Report a vulnerability on the affected repository. Only that repository's maintainers see the report, and you will hear back there.
Repositories with their own SECURITY.md (for example equantic-ui)
say what they support and how fast they answer; this file is the default for the ones that do not.