Feel free to build LibreELEC yourself if you are that concerned. All the code is public.
In the meantime I'd advise not downloading any unknown zip files
I mean, I personally am not concerned since I know about the issue. But all the other users who don't are vulnerable. I would atl east consider a blog post as a warning. Between the "hardcoded" SSH password and handling of this, I am concerned about LibreELEC's stance on user security, honestly.
Edit: 'Just to clarify, I'm not expecting people to work around the clock on a free project for me. I just think the issue should be handled differently. Let at least a part of your userbase know via blog posts, forum accouncements, etc. You may be the biggest distro for RPi devices, I think it's very important to take issues like this very seriously.