Hi maintainers, I have a security vulnerability report for this package that I'd like to share privately before any public disclosure. This repo doesn't have a SECURITY.md or private vulnerability reporting enabled, so I don't have a private channel to reach you. Could someone provide a contact, or enable private vulnerability reporting so I can submit through GitHub's own flow?
I already reported this through Samsung's PSIRT channel (apc.psirt@samsung.com), and their team recommended I open an issue here to get it formally tracked. I'm doing that, but I'm intentionally not including any technical details in this issue since the finding is a live, unpatched authentication bypass and this repo has no private reporting path yet. Happy to share full details, proof of concept, and reproduction steps as soon as there's a private way to send them.
Thanks.
Hi maintainers, I have a security vulnerability report for this package that I'd like to share privately before any public disclosure. This repo doesn't have a SECURITY.md or private vulnerability reporting enabled, so I don't have a private channel to reach you. Could someone provide a contact, or enable private vulnerability reporting so I can submit through GitHub's own flow?
I already reported this through Samsung's PSIRT channel (apc.psirt@samsung.com), and their team recommended I open an issue here to get it formally tracked. I'm doing that, but I'm intentionally not including any technical details in this issue since the finding is a live, unpatched authentication bypass and this repo has no private reporting path yet. Happy to share full details, proof of concept, and reproduction steps as soon as there's a private way to send them.
Thanks.