CryptPad security policy is detailed in the following document: https://cryptpad.org/security/.
Before reaching out about a potential vulnerability, ensure it falls within the scope of our project. Please read thoroughly our whitepaper describing our threat model and what we consider acceptable or not security-wise. If you are sure you found a real vulnerability, you can report it using the GitHub Security interface. You can also send us an email at security@cryptpad.org