Only the latest release receives security fixes while via is pre-1.0.
Please use GitHub private vulnerability reporting. Do not open a public issue for an undisclosed vulnerability.
via reads local RouteSpec JSON and writes files to a user-selected output directory. Reports involving path handling, unexpected file writes, unsafe SVG content, or plugin packaging are especially useful.