Hi,
I found a critical-severity vulnerability affecting this project as shipped (full unauthenticated access to customer PII, financial/invoice data, and destructive delete/write operations on every API endpoint). There's no SECURITY.md, no email listed on the org's GitHub profile or clawnify.com, and GitHub's private vulnerability reporting isn't enabled on this repo. I don't want to post exploit details in a public issue given the severity.
Could you enable GitHub's private vulnerability reporting (repo Settings -> Security -> "Private vulnerability reporting"), add a SECURITY.md with a contact email, or point me to a private channel? Happy to send full details immediately once there's a private channel.
Thanks,
kta1kri
Hi,
I found a critical-severity vulnerability affecting this project as shipped (full unauthenticated access to customer PII, financial/invoice data, and destructive delete/write operations on every API endpoint). There's no SECURITY.md, no email listed on the org's GitHub profile or clawnify.com, and GitHub's private vulnerability reporting isn't enabled on this repo. I don't want to post exploit details in a public issue given the severity.
Could you enable GitHub's private vulnerability reporting (repo Settings -> Security -> "Private vulnerability reporting"), add a SECURITY.md with a contact email, or point me to a private channel? Happy to send full details immediately once there's a private channel.
Thanks,
kta1kri