Hi — I'm a security researcher. I've identified what I believe is a security issue in SuperAGI (a path-traversal / arbitrary file write reachable through a standard agent tool). I'd like to disclose it privately and responsibly, with a proof of concept and a suggested fix.
I'm intentionally omitting technical detail here to avoid publicly disclosing an unpatched issue.
This repo currently has no SECURITY.md and GitHub Private Vulnerability Reporting appears to be disabled (Security → Advisories → "Report a vulnerability" is not available). Could you either:
- Enable Private Vulnerability Reporting (Settings → Code security → "Private vulnerability reporting"), so I can file a private advisory here; or
- Share a security contact / email for the report?
Happy to send the full write-up and PoC as soon as there's a private channel. Thanks!
Hi — I'm a security researcher. I've identified what I believe is a security issue in SuperAGI (a path-traversal / arbitrary file write reachable through a standard agent tool). I'd like to disclose it privately and responsibly, with a proof of concept and a suggested fix.
I'm intentionally omitting technical detail here to avoid publicly disclosing an unpatched issue.
This repo currently has no SECURITY.md and GitHub Private Vulnerability Reporting appears to be disabled (Security → Advisories → "Report a vulnerability" is not available). Could you either:
Happy to send the full write-up and PoC as soon as there's a private channel. Thanks!