Security vulnerability report - requesting private contact channel
Author: kta1kriCreated Sep 18, 2026Updated Sep 18, 2026
Hello Alluxio maintainers,
I'm an independent security researcher and I believe I've found a security vulnerability in Alluxio (a missing-authorization / path-traversal issue reachable via a standard client RPC option). I did not want to post technical details in a public issue.
I could not find a SECURITY.md, a security contact email, or GitHub Private Vulnerability Reporting enabled on this repository. Could someone from the security/maintainer team please provide a private channel (email or otherwise) where I can send the full report with technical details and a suggested severity assessment?
You can reach me at [email protected].
Thank you.
Source: Alluxio/alluxio