Do not open a public issue for a vulnerability that could put C2 users at risk. Report it privately through the security-advisory page of the affected plugin repository and notify the C2 maintainers through GitHub's private vulnerability reporting when available.
Catalog entries are metadata, not a sandbox or security endorsement. C2 extensions run with the user account's operating-system permissions after the user explicitly trusts them. Review a plugin's pinned source, permissions, subprocesses, and network behavior before enabling it.
Compromised, malicious, or abandoned entries may be marked unavailable or removed while an advisory is investigated.