Hi,
I wanted to let you know that I’ve opened a private security advisory for this repository, which includes a detailed report and proof of concept:
https://github.com/mozilla/node-convict/security/advisories/GHSA-44fc-8fm5-q62h
I just wanted to make sure it didn’t get missed. I’m happy to coordinate through the advisory or follow whatever disclosure process you prefer.
Best regards,
Kevin