If you believe you've found something in Django REST framework JSON:API which has security implications, please do not raise the issue in a public forum.
Use the security advisory to report a vulnerability instead.
The project maintainers will then work with you to resolve any issues where required, prior to any public disclosure.