If you find a vunerability in Crux, please imediately report it to security@joshuarocks.me. I will respond as soon as I can, and if no response if given within 3 days, please submit it as a Github issue. If it is not explotible in real world use, there is no need to email, you can just submit a github issue. If there is an vunerability in the underlying matrix-rust-sdk library itself, please report it to them here. Thank you!