Please report security issues privately through GitHub's private vulnerability reporting, not as a public issue.
Include the GoVec version (GET /api/v1/info reports it), how you run it, and the steps to
reproduce. GoVec is maintained by one person, so there is no guaranteed response time, but
reports are taken seriously and fixes are released as soon as practical.
GoVec is pre-1.0. Security fixes go into the latest release only.