Security: request to open a private disclosure channel
Author: mohammedix88Created Aug 13, 2026Updated Aug 16, 2026
Hi — I'm a security researcher (mohammad adnan, CyStack red team). I've identified what I believe is a security issue in jsbeautifier/cssbeautifier (the Python packages; affecting the current release) and would like to report it privately and responsibly.
I couldn't find a private channel: this repo's GitHub Private Vulnerability Reporting appears to be disabled (Security → Advisories → Report a vulnerability returns 404) and I didn't find a SECURITY.md contact. Could you either:
- Enable Private Vulnerability Reporting (Settings → Security → Private vulnerability reporting), or
- Share a security email / preferred private channel?
I have a runtime-verified proof-of-concept and a suggested one-line fix ready to share privately. I'm deliberately not posting details here to avoid public exposure before a fix. Thank you!
Source: beautifier/js-beautify