Skip to content

Security contact needed for responsible disclosure #281

Description

@Akshat-Parikh-pt

Hi maintainers, I have a security vulnerability report for this package that I'd like to share privately before any public disclosure. This repo doesn't have a SECURITY.md or private vulnerability reporting enabled, so I don't have a private channel to reach you. Could someone provide a contact, or enable private vulnerability reporting so I can submit through GitHub's own flow?

I already reported this through Samsung's PSIRT channel (apc.psirt@samsung.com), and their team recommended I open an issue here to get it formally tracked. I'm doing that, but I'm intentionally not including any technical details in this issue since the finding is a live, unpatched authentication bypass and this repo has no private reporting path yet. Happy to share full details, proof of concept, and reproduction steps as soon as there's a private way to send them.

Thanks.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions