You just have to assume that open source software is rife with bugs. Sometimes it's unintentional, other times they are malicious, effectively zero-day exploits.
Plenty of history here too. I remember the Heartbleed "bug" back in 2014 that compromised the openssl library. The effect was enormous.
More recently the log4j bug and of course the amount of npm fuckery is off the charts.
Check out the sneaky git commit on the attached pic, done when no-one would ever be looking.