lastpass / lastpass-cli

LastPass command line interface tool
GNU General Public License v2.0
2.85k stars 290 forks source link

Trying to get in touch regarding a security issue #608

Open JamieSlome opened 3 years ago

JamieSlome commented 3 years ago

Hello,

We have received a disclosure against this repository and I would like to share it with you. I could not find a contactable e-mail or security process to follow.

Could you create a SECURITY.md with an e-mail so that I can share it with you or just let me know of an e-mail address to send it to.

Let me know if you have any questions.

-- Jamie from huntr.dev

balintsera commented 3 years ago

Hi, sorry for the late response: please use our Bug Bounty program: https://bugcrowd.com/lastpass

ghost commented 2 years ago
Screen Shot 2021-08-12 at 11 15 01 AM

@balintsera hmm, it appears that the CLI is out of scope? If I am understanding this correctly, other security requests would be prioritized over anything related to the CLI. Does that sound accurate? Thanks!