Hi
I'm doing independent security research and found a security issue in this repo, separate from the one already tracked in #19/#29.
I don't see a SECURITY.md or GitHub private vulnerability reporting enabled on this repository, so I don't have a private channel to share the technical details safely.
I also noticed #29 (a security fix for a related-but-different issue) has been open since June 29 without a maintainer response, so I understand this project may not be actively maintained right now, no pressure, just flagging that I'll proceed on a standard disclosure timeline if I don't hear back.
Could you enable GitHub's private vulnerability reporting (Settings → Code security and analysis → Private vulnerability reporting), or share an alternate private contact?
I'll follow a 90-day coordinated disclosure timeline from today. If there's no response by then, I'll request a CVE directly through MITRE's CNA of Last Resort process, citing this issue and #29 as documentation of the disclosure attempt.
Happy to share full technical details the moment there's a private channel.
~ Shubham Chhatbar (shubhamchhatbar1@gmail.com)
Hi
I'm doing independent security research and found a security issue in this repo, separate from the one already tracked in #19/#29.
I don't see a SECURITY.md or GitHub private vulnerability reporting enabled on this repository, so I don't have a private channel to share the technical details safely.
I also noticed #29 (a security fix for a related-but-different issue) has been open since June 29 without a maintainer response, so I understand this project may not be actively maintained right now, no pressure, just flagging that I'll proceed on a standard disclosure timeline if I don't hear back.
Could you enable GitHub's private vulnerability reporting (Settings → Code security and analysis → Private vulnerability reporting), or share an alternate private contact?
I'll follow a 90-day coordinated disclosure timeline from today. If there's no response by then, I'll request a CVE directly through MITRE's CNA of Last Resort process, citing this issue and #29 as documentation of the disclosure attempt.
Happy to share full technical details the moment there's a private channel.
~ Shubham Chhatbar (shubhamchhatbar1@gmail.com)