Please report security-sensitive issues privately through GitHub's Security > Report a vulnerability flow rather than a public issue.
The native server binds to loopback and is intended for local use. Reports about unintended network exposure, unsafe file handling, or release-package tampering are especially useful.