GCWing / GCWing/OpenBitFun

Security: requesting a private channel to report a critical vulnerability (no details here)

未关闭
#1,045 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
question
主要语言
Rust
星标
2.3k
派生
231
平均合并
2 小时 49 分钟
30 天内合并 PR
589

描述

Hi maintainers 👋

I've identified what I assess as a **critical-severity security vulnerability** in BitFun, reproduced against the current `main` branch.

I'm **intentionally withholding all technical details here** — no affected file, component, mechanism, or proof-of-concept — because publicly disclosing an unpatched issue would put current users at risk. This follows the project's own `SECURITY.md` / coordinated-disclosure policy.

I already have a complete report ready to share **privately**, including:

- Root-cause analysis and the exact location
- A working, self-contained proof-of-concept
- CVSS 3.1 scoring
- A proposed patch (diff) plus a regression test

**What I need to proceed: a private channel.** Right now the repo's `/security/advisories/new` link isn't usable by non-maintainers because **Private Vulnerability Reporting appears to be disabled**. Please do one of:

1. **Enable Private Vulnerability Reporting** — repo **Settings → Code security and analysis → Private vulnerability reporting → Enable**. I'll then submit the full report through GitHub Security Advisories; or
2. Reply with a **private security contact** (e.g. a security email) I can send the report to.

Once a private channel is open I'll hand over everything immediately, and I'm happy to coordinate a disclosure timeline after you've had a chance to review and patch.

Flagging as high priority given the severity. Thanks for building BitFun! 🙏

贡献指南

打开贡献指南

调研方向

Start with the repository's SECURITY.md and the GitHub Security Advisories private-reporting entry point mentioned in the issue. The issue is complete when a private channel is enabled or a private security contact is provided so the withheld vulnerability report, proof of concept, proposed patch, and regression test can be shared.

由索引模型根据 Issue 内容生成。

评估

技术栈
rust
领域
security
Issue 类型
缺陷
难度
5/5
预计耗时
一周以上
活跃度
冷清
描述清晰度
需要澄清
新手友好度
15/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。