Help with security vulnerability in Forge app

There is already another thread here Forge custom fields with authorize in Forge app - which permission to use

I am also waiting for comment from Atlassian, either here or in AMS ticket. I have no idea why they set SLA of a month and completely ignore here in the community as well as in the ticket.