Advisory URL or ID: GHSA-jwj6-pxj6-9q8g
Package / Ecosystem: kurrier / npm
Repo: kurrier-org/kurrier
Type of Improvement: Add missing credit
Hello GitHub Security Curation Team,
I am requesting credit addition on published advisory GHSA-jwj6-pxj6-9q8g for repository kurrier-org/kurrier.
- Prior Disclosure: I reported these exact vulnerabilities (S3 arbitrary upload, raw email IDOR, and unauthenticated Server Actions) via GitHub PVR under draft GHSA-959c-cf43-82f4 (Part 3/5) on August 11, 2026.
- Publication Conflict: The maintainer published GHSA-jwj6-pxj6-9q8g covering these identical findings without linking the open draft or assigning credit.
- Inaction: I requested co-credit inside the private draft thread 5 days ago, but the maintainer remains active in Git commits while leaving the PVR thread unaddressed.
Please verify the PVR timestamps for GHSA-959c-cf43-82f4 and add my GitHub handle (@shellcobra) as a Finder/Reporter to GHSA-jwj6-pxj6-9q8g.
Advisory URL or ID: GHSA-jwj6-pxj6-9q8g
Package / Ecosystem: kurrier / npm
Repo: kurrier-org/kurrier
Type of Improvement: Add missing credit
Hello GitHub Security Curation Team,
I am requesting credit addition on published advisory GHSA-jwj6-pxj6-9q8g for repository kurrier-org/kurrier.
Please verify the PVR timestamps for GHSA-959c-cf43-82f4 and add my GitHub handle (@shellcobra) as a Finder/Reporter to GHSA-jwj6-pxj6-9q8g.