To securely report a vulnerability, please open an advisory on GitHub or report it by sending an email to koukun0120@gmail.com.
Security: yamadashy/repomix
Security
SECURITY.md
-
Cleartext Credential Exposure via Unredacted URL Logging in Remote Repository ProcessingGHSA-w8cw-mgw9-74h7 published
Aug 11, 2026 by yamadashyModerate -
Repomix MCP file system tools claimed protections that were not implementedGHSA-rpmv-562j-qxrv published
Aug 11, 2026 by yamadashyLow -
attach_packed_output can bypass file-read secret scanning for supported local filesGHSA-hwpp-h97w-2h3j published
May 27, 2026 by yamadashyModerate -
Command Injection (RCE) via `--remote-branch` Argument InjectionGHSA-9mm9-rqhj-j5mx published
May 27, 2026 by yamadashyHigh
Learn more about advisories related to yamadashy/repomix in the GitHub Advisory Database