If you find a security vulnerability in any of my repositories, do not open a public issue.
Please report it privately:
- Open a private advisory: GitHub → Security → Report a vulnerability on the affected repository, or
- Email the details (reproduction steps, impact, suggested fix) to the account owner via GitHub
You should receive a response within 48 hours. Please do not disclose the issue publicly until a fix has been shipped.
- Repositories owned by
riteshekbote - Research/CTF material in those repositories
Out of scope: forks of third-party projects (report upstream instead), and public vulnerability-disclosure programs — report those to the program's own channels.
- You report privately (advisory or email).
- Maintainer confirms and triages within 48h.
- Fix is prepared, tested, and released.
- You are credited (if you wish) once the fix ships.