Should I manually resolve WP Core File security issues or await a subsequent WP release?

Most of the time you should not modify core by yourself – it will get overwritten after update and it may cause some conflicts.

Of course, if you know what you’re doing and the vulnerability is really serious, then you can update given library and test everything by yourself.

As for awareness. Most of the times WP is very aware of vulnerabilities in its code and fixes them with minor releases.

You can check if the problem is known and if it has a ticket in Trac:

And if you can’t find anything, you can always report it: