Report it privately, through GitHub: on the affected repository, open the Security tab and choose Report a vulnerability. Private vulnerability reporting is turned on for every public repository in this organization, and a report made that way is visible only to the maintainers until it is published.
Please do not open a public issue for a vulnerability. Issues here are read and worked by automation, in public, and an agent would set about reproducing it.
A report is most useful when it carries what any report here carries: the command, the directory, and the version or commit, what happened, and what should have happened instead — plus what an attacker gains.
These are developer tools that run on your machine, against your repositories, with your credentials. Of particular interest:
- a repository's content — a plan, a template, a configuration file, a citation — causing a tool to run a command, or to write outside the places it says it writes;
- a tool sending a credential, a token, or site-specific data somewhere its documentation does not say it goes;
- a gate (
grund check,fissile check) that can be made to pass over a tree it did not read.
A tool doing what its documentation says, run on a repository you chose to
trust, is not a vulnerability: rhei runs the programs a plan names, and
ephor runs the actions its configuration names. That is what they are for.
The latest release of each tool. Fixes are not backported.