Only the latest release gets security fixes. Update before reporting, if you can.
Please don't open a public issue for a security problem.
Report it privately through GitHub's security advisories: Report a vulnerability.
Useful things to include: what an attacker can do, the steps to reproduce it, the Vibe version and the macOS or iOS version you saw it on, and — since most of the attack surface is file parsing — a sample file, if one triggers it.
You should get a first response within a week. Once a fix ships you'll be credited in the advisory, unless you'd rather not be.