MetaMask / MetaMask/metamask-sdk

Urgent: Vulnerability Report Stuck in the Sorting Queue for Over a Month (HackerOne)

Open
#1,393 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
338
Forks
260
PR merge metrics
No merged PRs in 30d

Description

### SDK

Web

### Provide environment information

Message:

Hello MetaMask Engineering and Security Teams,

I am opening this ticket to escalate an administrative standstill regarding a critical vulnerability report submitted through your official HackerOne bug bounty program.

The report contains a fully functional Proof of Concept (PoC) demonstrating a critical impact. However, despite your program's stated Service Level Agreement (SLA) objectives, the ticket has received no substantive updates from the support team or any sorting progress for nearly a month.

Out of respect for user asset security and responsible disclosure protocols, I have maintained strict confidentiality and have not disclosed any technical details or steps for reproducing the vulnerability. However, the lack of response through the proper channels is extremely concerning.

I urge an experienced security engineer or program manager to review the critical queue pending on HackerOne immediately and provide a real-time update on the report's status on the platform.

Thank you.

### MetaMask SDK Version

N/A

### MetaMask Mobile app Version

N/A

### What browser are you using? (if relevant)

_No response_

### How are you deploying your application? (if relevant)

_No response_

### Describe the Bug

Urgent: Vulnerability Report Stuck in the Sorting Queue for Over a Month (HackerOne)

### Expected Behavior

Urgent: Vulnerability Report Stuck in the Sorting Queue for Over a Month (HackerOne)

### Link to reproduction - Issues with a link to complete (but minimal) reproduction code will be addressed faster

_No response_

### To Reproduce

Urgent: Vulnerability Report Stuck in the Sorting Queue for Over a Month (HackerOne)

Contributor guide

Open the contributing guide

Research direction

No source file, test, reproduction, or technical vulnerability details are provided in the issue. Start by reviewing the referenced HackerOne report and its sorting status; the requested outcome is a substantive status update from the security team through the appropriate platform, not a code change.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.