Skip to content

Requesting private channel for reporting a vulnerability #35

Description

@Shubham-0-0-7

Hi
I'm doing independent security research and found a security issue in this repo, separate from the one already tracked in #19/#29.
I don't see a SECURITY.md or GitHub private vulnerability reporting enabled on this repository, so I don't have a private channel to share the technical details safely.
I also noticed #29 (a security fix for a related-but-different issue) has been open since June 29 without a maintainer response, so I understand this project may not be actively maintained right now, no pressure, just flagging that I'll proceed on a standard disclosure timeline if I don't hear back.
Could you enable GitHub's private vulnerability reporting (Settings → Code security and analysis → Private vulnerability reporting), or share an alternate private contact?
I'll follow a 90-day coordinated disclosure timeline from today. If there's no response by then, I'll request a CVE directly through MITRE's CNA of Last Resort process, citing this issue and #29 as documentation of the disclosure attempt.

Happy to share full technical details the moment there's a private channel.

~ Shubham Chhatbar (shubhamchhatbar1@gmail.com)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions