Yeah, I just stumbled across the post - the disclosure wasn’t made by me. Since it was already public, I figured the best place to get visibility was the forum and an issue.
I looked in the repos, erpnext.org, and frappe.io. Looks like it was on erpnext.com (though I’m not sure how to actually reach that page through the navigation without a direct link).
I’m just stating the experience I went through trying to find the security disclosure contact information for the project. I don’t know what others think. You can make the call as to where to place the information.