If you've found a vulnerability AND you have a proof of exploitation (either theoretical or practical) you can contact https://uav4geo.com/contact to report it.
Please DO NOT contact us if one of our dependencies has a newly reported CVE! Having a CVE does not always mean a vulnerability is exploitable. Only contact us if you have a proof of exploitation in WebODM!