IntelLabs / IntelLabs/Xe-Forge

Security: how to report a vulnerability (private reporting disabled)

Open
#49 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
21
Forks
8
PR merge metrics
No merged PRs in 30d

Description

Hi maintainers,

I'm a security researcher (Moshe Levi, LevinityCyber) with a coordinated security
report for Xe-Forge. I'm not including any vulnerability details in this public issue.

Your SECURITY.md points to Intel's vulnerability-handling guidelines, but I'd prefer
a direct, private channel for this repo. GitHub Private Vulnerability Reporting is not
enabled here (Security > Advisories has no "Report a vulnerability" option).

Could you please either:
1. Enable GitHub Private Vulnerability Reporting on this repo
(Settings > Code security > Private vulnerability reporting), or
2. Confirm the best private contact for a coordinated disclosure on Xe-Forge?

I'll send the full write-up and a reproducible proof-of-concept as soon as there's a
private channel. Requesting standard coordinated disclosure and credit as
"Moshe Levi, LevinityCyber".

Thanks!
Moshe@levinitycyber.com

Contributor guide

Open the contributing guide

Research direction

Start by reading SECURITY.md and checking the repository's Settings > Code security > Private vulnerability reporting option. Confirm that a private reporting channel is available and that SECURITY.md clearly directs researchers to it; otherwise document the approved private contact or reporting path.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
security
Issue type
Documentation
Difficulty
1/5
Estimated time
Under an hour
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.