Security fixes target the latest Cargo-Rail release. Report a vulnerability even if you found it in an older release; include every version or commit you tested.
Submit the report through GitHub's private vulnerability form. Do not put vulnerability details in a public issue, discussion, pull request, or commit.
Include:
- the affected Cargo-Rail version or commit;
- the operating system, target, Rust toolchain, and installation method when relevant;
- the security impact and required attacker access;
- the smallest reliable reproduction or proof of concept; and
- known mitigations or a suggested fix, if available.
If GitHub Security Advisories are unavailable, email thealiaslab@gmail.com with the same information. Keep the report
private until a fix is released or a disclosure timeline is agreed.