Security vulnerabilities related to Superset core should follow the instructions within Apache Superset's SECURITY.md file.
Please only report security vulnerabilities pertaining to GeoSet functionality. Send an email to ebienstock@teamraft.com describing the vulnerability and we'll reach out shortly.