There is a vulnerability in the Graphite library:
Reportedly the problems have been patched in version 1.3.5 of Graphite2. 
  But the version of xetex I'm using (3.14159265-2.6-0.99992, from the 
TeX Live 2015 distro) says it uses Graphite2 v1.2.3.  Will the next TeX 
Live distro's version of xetex use >= v.1.3.5?
