Report suspected Pliego vulnerabilities privately through GitHub Security Advisories. Include the affected version or commit, platform, impact, and the smallest safe reproduction you can provide. Do not open a public issue for an undisclosed vulnerability.
If the issue is inherited from Servo, Pliego maintainers will coordinate the upstream report and downstream fix as appropriate.