Security: preferred private channel to report a vulnerability?
Author: mohammedix88Created Aug 11, 2026Updated Aug 11, 2026
Hi — I'm a security researcher. I've identified what I believe is a security issue in SuperAGI (a path-traversal / arbitrary file write reachable through a standard agent tool). I'd like to disclose it privately and responsibly, with a proof of concept and a suggested fix.
I'm intentionally omitting technical detail here to avoid publicly disclosing an unpatched issue.
This repo currently has no SECURITY.md and GitHub Private Vulnerability Reporting appears to be disabled (Security → Advisories → "Report a vulnerability" is not available). Could you either:
- Enable Private Vulnerability Reporting (Settings → Code security → "Private vulnerability reporting"), so I can file a private advisory here; or
- Share a security contact / email for the report?
Happy to send the full write-up and PoC as soon as there's a private channel. Thanks!
Source: TransformerOptimus/SuperAGI