FedML-AI / FedML-AI/FedML

Please enable private vulnerability reporting (no security channel currently exists)

Open
#2,267 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
4.1k
Forks
765
PR merge metrics
No merged PRs in 30d

Description

Hi — a security-process request, deliberately with no technical detail in it.

I have a security finding to report in FedML and there is currently no way to send it privately: **private vulnerability reporting is disabled** on this repository (`/security/advisories/new` returns 404) and there is no `SECURITY.md` with a contact address.

That leaves a researcher choosing between staying silent and describing the issue in a public issue where anyone can read it before there is a fix. Neither is good for the people running FedML, so I am asking for the channel rather than using either.

**The ask:** `Settings → Advanced Security → Private vulnerability reporting → Enable`. It takes a few seconds and costs nothing.

**Why this is worth those seconds.** FedML already has two CVEs assigned this year (CVE-2026-5535 and CVE-2026-5536), both recorded as having been reported without a response. Both were published as **unreviewed** records with no package metadata, which means dependency scanners cannot match them and your users get no automated signal at all. A private channel plus a published advisory fixes that: an advisory feeds OSV and Dependabot, and a CVE can be requested directly from it.

**Happy to do the work.** If you enable reporting I will file a complete report through it — affected files and lines, CVSS vector, affected version range, and references — written so you can review and publish rather than having to write it up yourselves. I will also state plainly which parts I have verified by reading the released source and which I have not tested at runtime, so nothing is taken on trust.

If maintaining this repository is no longer a priority, that is a fair answer too — even a `SECURITY.md` naming an email address, or archiving with a pointer to a successor, would be better for users than the current silence.

No deadline from my side.

— Mohammad Adnan (CyStack)

Contributor guide

Open the contributing guide

Research direction

Open the repository Settings → Advanced Security page and check the Private vulnerability reporting setting; the issue reports that /security/advisories/new returns 404. Done means private reporting is enabled, or a SECURITY.md contact path is added as the documented alternative.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
security
Issue type
Feature
Difficulty
1/5
Estimated time
Under an hour
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.