Hi EBAD maintainers,
I'm a security researcher who has found several security vulnerabilities in the EBAD codebase during a responsible review. Some of these are significant (command injection, credential exposure).
I'd like to report them privately, but I noticed that:
- The repo does not have GitHub Private Vulnerability Reporting enabled
- There is no security contact email configured
Could you please either:
I will share the findings privately once a secure channel is available.
Thank you for maintaining this project.
Best regards,
Wernerina (GitHub)
Hi EBAD maintainers,
I'm a security researcher who has found several security vulnerabilities in the EBAD codebase during a responsible review. Some of these are significant (command injection, credential exposure).
I'd like to report them privately, but I noticed that:
Could you please either:
I will share the findings privately once a secure channel is available.
Thank you for maintaining this project.
Best regards,
Wernerina (GitHub)