This vulnerability is referenced as CVE-2026-13484. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A reply to the GitHub issue explains, that "[t]he labeling schema PR has not been merged yet. The auth handlers will be added before the release."
SOCIAL SHARE CARD GENERATOR