If you believe you have found a security vulnerability in vecstore-sdk, report it privately through GitHub security advisories. Do not open a public issue.
You get a response within seven days. A fix for a confirmed report ships in a release, and that release's notes disclose the issue.