First, please keep in mind that liblsl is meant to be used in a closed, trusted and isolated lab environment, and is not meant to be exposed to a public internet or network environment.
With that said, security vulnerabilites will still be taken seriously, but because this is a small, open source project, please just report the issue via Github issues. If you feel that your concern is extremely urgent, please use one of the channels listed in the SUPPORT.md file to get in touch with the maintainers.