I contacted the developers about the issue, including versions affected, the exploit, and the fix. Within 5 minutes, I had a response saying, in effect that they "cannot be responsible for the user not knowing".
I'd submit a fix myself, but there's no place to do so. It's an open-source app but you cannot commit publicly. I want them to fix this because it's an extremely simple patch, and the potential damage resulting from an exploit would be crippling.
If I blog about it, or otherwise publicly post details, people could get hurt. If I don't, the developers have no reason (or rather, motivation) to fix it.
Advice?