This has already been reported before as issue #500 (replicated over here) and has been fixed in 47110d7. Unfortunately, this problem still persist for users of bower - which will pull a version of bootstrap-multiselect with the vulnerability.
Could you release a new version thereby allowing bower users to receive the update also?