Ubuntu has issued an advisory on September 22: https://ubuntu.com/security/notices/USN-5085-1 The issue is fixed upstream in 0.4.2.
Status comment: (none) => Fixed upstream in 0.4.2
Fix in cauldron with 0.4.2-1.mga9 by Guillaume.
Status: NEW => RESOLVEDResolution: (none) => FIXEDCC: (none) => jani.valimaa