The security policy asks to only report security issues through the Meta Bug Bounty. This requires a Facebook account however. To report an issue, I actually attempted to create one, but it was suspended and permanently disabled during the prove-you-are-not-a-bot flow before I could log in the first time (I didn't get an explanation why and do not know what went wrong). I thus find myself unable to report issues to you without doing so publicly. If you would like to receive bug reports with security impacts non-publicly, I suggest you offer also an alternative path to do so that does not rely on having a Facebook account.