I found a critical security vulnerability in the file manager's upload handler that allows cross-tenant file writes (potential RCE against other customers' websites). There's no SECURITY.md or GitHub private vulnerability reporting on this repo, so I'm not posting technical details here.
I've emailed contact@crivion.com with the full write-up. If that's not the right address, could you point me to a private channel (email, GHSA collaborator invite, etc.)? Happy to wait for a fix before any detail becomes public.
I found a critical security vulnerability in the file manager's upload handler that allows cross-tenant file writes (potential RCE against other customers' websites). There's no SECURITY.md or GitHub private vulnerability reporting on this repo, so I'm not posting technical details here.
I've emailed contact@crivion.com with the full write-up. If that's not the right address, could you point me to a private channel (email, GHSA collaborator invite, etc.)? Happy to wait for a fix before any detail becomes public.