GCWing / GCWing/OpenBitFun

Security: requesting a private channel to report a critical vulnerability (no details here)

Đang mở
#1,045 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
question
Ngôn ngữ chính
Rust
Star
2.3k
Fork
231
Merge trung bình
2 giờ 49 phút
Pull request đã merge (30 ngày)
589

Mô tả

Hi maintainers 👋

I've identified what I assess as a **critical-severity security vulnerability** in BitFun, reproduced against the current `main` branch.

I'm **intentionally withholding all technical details here** — no affected file, component, mechanism, or proof-of-concept — because publicly disclosing an unpatched issue would put current users at risk. This follows the project's own `SECURITY.md` / coordinated-disclosure policy.

I already have a complete report ready to share **privately**, including:

- Root-cause analysis and the exact location
- A working, self-contained proof-of-concept
- CVSS 3.1 scoring
- A proposed patch (diff) plus a regression test

**What I need to proceed: a private channel.** Right now the repo's `/security/advisories/new` link isn't usable by non-maintainers because **Private Vulnerability Reporting appears to be disabled**. Please do one of:

1. **Enable Private Vulnerability Reporting** — repo **Settings → Code security and analysis → Private vulnerability reporting → Enable**. I'll then submit the full report through GitHub Security Advisories; or
2. Reply with a **private security contact** (e.g. a security email) I can send the report to.

Once a private channel is open I'll hand over everything immediately, and I'm happy to coordinate a disclosure timeline after you've had a chance to review and patch.

Flagging as high priority given the severity. Thanks for building BitFun! 🙏

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Start with the repository's SECURITY.md and the GitHub Security Advisories private-reporting entry point mentioned in the issue. The issue is complete when a private channel is enabled or a private security contact is provided so the withheld vulnerability report, proof of concept, proposed patch, and regression test can be shared.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
rust
Lĩnh vực
security
Loại issue
Lỗi
Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Cần làm rõ
Mức phù hợp với người mới
15/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.