Security flaw found in open-source tool