Trying to get in touch regarding a security issue
See original GitHub issueHey there!
I belong to an open source security research community, and a member (@haxatron) has found an issue, but doesn’t know the best way to disclose it.
If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.
Thank you for your consideration, and I look forward to hearing from you!
(cc @huntr-helper)
Issue Analytics
- State:
- Created 2 years ago
- Comments:5 (3 by maintainers)
Top Results From Across the Web
Get help with security issues - Apple Support
Learn about security documentation and resources for developers. Contact Apple Developer Support to request assistance with certificate ...
Read more >Respond to security alerts - Google Account Help
Go to your Google Account. On the Security issues found panel, click Secure account. If the activity was you. On the security alert,...
Read more >Report a Security Issue - Amazon Customer Service
To report a security vulnerability on Amazon Retail services or products: Submit the details of your findings through the web form, or visit...
Read more >How To Spot, Avoid, and Report Tech Support Scams
Real security warnings and messages will never ask you to call a phone number. Online ads and listings in search results pages. Tech...
Read more >Contact us - Login.gov
Get in touch. Contact the government agency to help you with your application status, membership, eligibility, benefits or other concerns related to your ......
Read more >
Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free
Top Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found

Thanks for the report. I believe this is a valid issue in ShellJS, so I’ve created a fix and pushed a release.
If you believe this patch is insufficient, please let me know privately via email and I’ll gladly investigate further.
The report should be public now. I recommend folks upgrade to ShellJS 0.8.5 to ensure you have the fix.
This bug only impacts the synchronous version of
shell.exec(). All other ShellJS methods (including the async usage ofshell.exec()) should not be impacted, however it’s of course perfectly safe to update ShellJS anyway.