Do not use public issues for a suspected vulnerability. Use GitHub's private vulnerability reporting feature when it is available for this repository.
The editor server is a local development tool. It has file-write routes with no authentication. Bind it to 127.0.0.1 and do not expose it to a public network.