Skip to content

Security: preferred private channel to report a vulnerability? #1582

Description

@mohammedix88

Hi — I'm a security researcher. I've identified what I believe is a security issue in SuperAGI (a path-traversal / arbitrary file write reachable through a standard agent tool). I'd like to disclose it privately and responsibly, with a proof of concept and a suggested fix.

I'm intentionally omitting technical detail here to avoid publicly disclosing an unpatched issue.

This repo currently has no SECURITY.md and GitHub Private Vulnerability Reporting appears to be disabled (Security → Advisories → "Report a vulnerability" is not available). Could you either:

  1. Enable Private Vulnerability Reporting (Settings → Code security → "Private vulnerability reporting"), so I can file a private advisory here; or
  2. Share a security contact / email for the report?

Happy to send the full write-up and PoC as soon as there's a private channel. Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions