If you think you have found a vulnerability in a roobli project, report it through GitHub's private advisory form on that repository. Do not open a public issue with a working exploit.
Noto's security boundaries are its release fuses, its content security policy, the capability broker for plugins, and the loopback-only remote control. A report that crosses one of them is the most useful kind.
We will not publish a bounty schedule. If the report is real, we will answer.