It looks like reCAPTCHA is not correctly implemented and the protection can be easily bypassed. Not providing exact details here to not expose organizations that are using this fork to bot attacks, but the bypass is trivial and has been confirmed in testing. Please make sure to correctly verify the value of g-recaptcha-response when sending invites.