We are unable to reproduce this on any of the 3.5.x series or 3.6.x development branch. The userid parameter is run through our filtering system as an unsigned integer. 'userid' => TYPE_UINT