Hello, and thank you for Kirara AI.
I think I have found a security issue in one of the repository's GitHub Actions workflows, and I would like to report it privately rather than describe it in a public issue — a public description would effectively be a disclosure before you have had a chance to act.
I could not find a private channel for the project: there is no SECURITY.md, and GitHub's private vulnerability reporting does not appear to be enabled. Could you either:
- enable private vulnerability reporting (Settings → Security → Private vulnerability reporting), or
- add a
SECURITY.md with a contact, or
- share a security contact (email / other) here,
so I can send the details privately? Once a channel exists I will send the full write-up, which includes the affected file, the exact lines, and a suggested fix. It is a workflow-configuration issue rather than anything in the deployed bot, and I have not run anything against your infrastructure.
Thank you for your time.
你好,感谢你们开发 Kirara AI。
我认为在仓库的某个 GitHub Actions workflow 中发现了一个安全问题,希望私下报告,而不是在公开 issue 中描述——公开描述相当于在你们处理之前就披露了漏洞。
我没有找到私密的报告渠道:仓库没有 SECURITY.md,也似乎没有启用 GitHub 的私密漏洞报告功能。能否请你们:
- 启用 Private vulnerability reporting(Settings → Security),或
- 添加带联系方式的
SECURITY.md,或
- 在此处提供一个安全联系方式(邮箱等)?
有了渠道之后,我会把完整说明(涉及的文件、具体行号和修复建议)私下发给你们。这是一个 workflow 配置问题,与已部署的机器人本身无关,我也没有对你们的基础设施进行任何测试。
谢谢!
Disclosure: I used an AI assistant to help find this and to draft this message; I verified the workflow file myself. / 说明:我借助了 AI 助手来发现问题并起草此消息,workflow 文件由我本人核实。
Hello, and thank you for Kirara AI.
I think I have found a security issue in one of the repository's GitHub Actions workflows, and I would like to report it privately rather than describe it in a public issue — a public description would effectively be a disclosure before you have had a chance to act.
I could not find a private channel for the project: there is no
SECURITY.md, and GitHub's private vulnerability reporting does not appear to be enabled. Could you either:SECURITY.mdwith a contact, orso I can send the details privately? Once a channel exists I will send the full write-up, which includes the affected file, the exact lines, and a suggested fix. It is a workflow-configuration issue rather than anything in the deployed bot, and I have not run anything against your infrastructure.
Thank you for your time.
你好,感谢你们开发 Kirara AI。
我认为在仓库的某个 GitHub Actions workflow 中发现了一个安全问题,希望私下报告,而不是在公开 issue 中描述——公开描述相当于在你们处理之前就披露了漏洞。
我没有找到私密的报告渠道:仓库没有
SECURITY.md,也似乎没有启用 GitHub 的私密漏洞报告功能。能否请你们:SECURITY.md,或有了渠道之后,我会把完整说明(涉及的文件、具体行号和修复建议)私下发给你们。这是一个 workflow 配置问题,与已部署的机器人本身无关,我也没有对你们的基础设施进行任何测试。
谢谢!
Disclosure: I used an AI assistant to help find this and to draft this message; I verified the workflow file myself. / 说明:我借助了 AI 助手来发现问题并起草此消息,workflow 文件由我本人核实。