OptimalScale / OptimalScale/LMFlow

Security: request for a private disclosure contact

Open
#973 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
8.5k
Forks
822
PR merge metrics
No merged PRs in 30d

Description

Hi,

I've found what I believe is a security issue in how LMFlow loads a model during inference, and I'd like to
report it privately and responsibly.

This repository doesn't have a SECURITY.md or GitHub Private Vulnerability Reporting enabled, so could you either
share a security contact email, or enable "Private vulnerability reporting" under Settings → Security → Advisories?

I'm keeping details out of this public issue on purpose. I'll send a full write-up and a proof-of-concept as soon as
there's a private channel. Thanks!

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No file, test, or entry point is named, and the reporter intentionally withholds vulnerability details. Review the repository's security-reporting setup and the GitHub advisory settings referenced in the issue; the request is complete when a private reporting channel is established and documented.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.