Hi,
I would like to report a vulnerability which I found in your npm package total.js (>3.4.7)
In accordance with responsible disclosure practices I would be happy to report it via a GitHub security advisory (https://github.com/totaljs/framework/security/advisories/new) and coordinate with you on a fix.
Best regards,
Kevin