Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
Hello @williamdes,

Thank you for the feedback. I have corrected the Supported Versions table to align with the actual project releases (v3.2.2,v3.2.1) as requested.

The reason for this SECURITY.md proposal is that I have discovered a Critical Remote Code Execution (RCE) vulnerability in the library. It is an Insecure Deserialization (CWE-502) flaw that allows an unauthenticated attacker to execute arbitrary system commands by leveraging the @type property.

I have a detailed technical report and a Proof of Concept (PoC) ready to share. Please let me know the preferred secure channel to disclose the full details, or consider enabling GitHub Private Vulnerability Reporting so I can submit it here privately.

I would also like to assist in coordinating a fix and assigning a CVE ID for this issue.

Best regards, @TheDeepOpc