If you encounter a security vulnerability in Tinybox, please use the Security tab in this GitHub repo to report it privately to me.
Please don't use the issue tracker to report a security vulnerability; this will make it public. Using the Security tab keeps the report private. Once a report is sent, I'll keep in touch with my progress, and when fixed will publish a security advisory with credit to you.