#2827·ast-grep

Security vulnerability report – request for a private disclosure channel

Author: Xzhong6Created Jul 20, 2026Updated Jul 22, 2026

Hello maintainers,

I believe I have identified a potentially high-impact security vulnerability in ast-grep.

I would prefer not to disclose the technical details publicly before the issue has been reviewed and, if necessary, fixed. I could not find an enabled private vulnerability reporting form or another private security reporting channel.

Could you please provide a preferred private contact method, enable GitHub private vulnerability reporting, or create a draft GitHub Security Advisory and invite me as a collaborator?

I can provide the affected components, complete source-to-sink analysis, a minimal proof of concept, impact assessment, and suggested remediation.

Thank you.