Mockintosh depends on pybars4 which is also maintained by UP9.
I recently discovered a vulnerability in the pybars3 template engine that also affects pybars4.
Private vulnerability reporting is not enabled for pybars4 on GitHub and no security contact is provided.
What would be the preferred channel to disclose the vulnerability?
Mockintosh depends on pybars4 which is also maintained by UP9.
I recently discovered a vulnerability in the pybars3 template engine that also affects pybars4.
Private vulnerability reporting is not enabled for pybars4 on GitHub and no security contact is provided.
What would be the preferred channel to disclose the vulnerability?