The latest released version of jQuery UI is supported.
Please email security@jquery.com, and we will respond as quickly as possible.
If the vulnerability is considered valid and accepted, a patch will be made for the latest jQuery UI version. If the vulnerability is deemed invalid, no further action is required.