Hi, I found a security issue affecting this repo and do not want to post exploit details publicly. I saw the security policy page, but GitHub private vulnerability reporting appears disabled from the API. Is there a preferred private security contact, or can PVR be enabled?
High-level, non-sensitive summary only: this concerns allowed path boundary behavior in filepath handling. I have not posted exploit details here.
Hi, I found a security issue affecting this repo and do not want to post exploit details publicly. I saw the security policy page, but GitHub private vulnerability reporting appears disabled from the API. Is there a preferred private security contact, or can PVR be enabled?
High-level, non-sensitive summary only: this concerns allowed path boundary behavior in filepath handling. I have not posted exploit details here.