Report it privately, never in a public issue: open a report with GitHub's private vulnerability reporting on the affected repository (its Security tab, then Report a vulnerability). If it is about the ZeroCaptcha service itself rather than the code here, report it the same way on the zerocaptcha repository.
Please include what you found, how to reproduce it, and what an attacker could do with it. We reply as soon as we can, fix what is confirmed, and credit you in the advisory if you wish.
If you committed or leaked a ZeroCaptcha API key (zc_live_…), revoke it on the dashboard's API keys page straight away and create a new one. A revoked key stops working at once.
Only the latest commit on each repository's main branch is supported.