

Oh, I know (I am a greying wizard), but why should the editor care? In theory, it should assume XCF, with the opened JPEG as the first layer.
Instead, it’s gotchas and RTFM. Which is sadly a very poor approach when developing a tool used by creatives who are vastly less likely to RTFM than the engineers making the tool.







You’re going to need to back up your claim otherwise you might as well be lying as there’s no CVE like this I can find nor any public disclosure.
Plex have a bug bounty program and a responsive security team too.
Post your security report.