Have submitted confidentially pull requests that fix both their main branch and currently released version.
(yes, I manually backported the fix from main branch to their last release because the vulnerability is that critical to fix)
Awaiting response from the project maintainers now.
Update: working with the maintainers to release a fix ASAP, but details of the vulnerability will be embargoed until admins have had a chance to upgrade.