GCWing / GCWing/OpenBitFun

Security: requesting a private channel to report a critical vulnerability (no details here)

オープン
#1,045 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
question
主要言語
Rust
スター
2.3k
フォーク
231
平均マージ
2時間 46分
マージ済み PR(30日)
577

説明

Hi maintainers 👋

I've identified what I assess as a **critical-severity security vulnerability** in BitFun, reproduced against the current `main` branch.

I'm **intentionally withholding all technical details here** — no affected file, component, mechanism, or proof-of-concept — because publicly disclosing an unpatched issue would put current users at risk. This follows the project's own `SECURITY.md` / coordinated-disclosure policy.

I already have a complete report ready to share **privately**, including:

- Root-cause analysis and the exact location
- A working, self-contained proof-of-concept
- CVSS 3.1 scoring
- A proposed patch (diff) plus a regression test

**What I need to proceed: a private channel.** Right now the repo's `/security/advisories/new` link isn't usable by non-maintainers because **Private Vulnerability Reporting appears to be disabled**. Please do one of:

1. **Enable Private Vulnerability Reporting** — repo **Settings → Code security and analysis → Private vulnerability reporting → Enable**. I'll then submit the full report through GitHub Security Advisories; or
2. Reply with a **private security contact** (e.g. a security email) I can send the report to.

Once a private channel is open I'll hand over everything immediately, and I'm happy to coordinate a disclosure timeline after you've had a chance to review and patch.

Flagging as high priority given the severity. Thanks for building BitFun! 🙏

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start with the repository's SECURITY.md and the GitHub Security Advisories private-reporting entry point mentioned in the issue. The issue is complete when a private channel is enabled or a private security contact is provided so the withheld vulnerability report, proof of concept, proposed patch, and regression test can be shared.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
rust
領域
security
issue の種類
バグ
難易度
5/5
見積もり時間
1週間以上
活発さ
静か
明瞭さ
説明が足りない
初心者へのやさしさ
15/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。