Please report vulnerabilities through a private GitHub security advisory. Do not open a public issue for a working exploit or unintended file access.
Include the Omaroll version, the shortest reproduction you can provide, and the media format or storage type involved.