Security vulnerability report – request for a private disclosure channel
Author: Xzhong6Created Jul 20, 2026Updated Jul 22, 2026
Hello maintainers,
I believe I have identified a potentially high-impact security vulnerability in ast-grep.
I would prefer not to disclose the technical details publicly before the issue has been reviewed and, if necessary, fixed. I could not find an enabled private vulnerability reporting form or another private security reporting channel.
Could you please provide a preferred private contact method, enable GitHub private vulnerability reporting, or create a draft GitHub Security Advisory and invite me as a collaborator?
I can provide the affected components, complete source-to-sink analysis, a minimal proof of concept, impact assessment, and suggested remediation.
Thank you.
Source: ast-grep/ast-grep