langgenius / langgenius/dify

Security Report Follow-up — No Response After Nearly Three Weeks

Open
#42,300 0 comments 1 reaction 0 assignees View on GitHub
🐞 bug
Dominant language
TypeScript
Stars
156k
Forks
24.6k
Avg merge
22h 9m
Merged PRs (30d)
610

Description

### Self Checks

- [x] I have read the [Contributing Guide](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) and [Language Policy](https://github.com/langgenius/dify/issues/1542).
- [x] This is only for bug report, if you would like to ask a question, please head to [Discussions](https://github.com/langgenius/dify/discussions/categories/general).
- [x] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify/issues), including closed ones.
- [x] I confirm that I am using English to submit this report, otherwise it will be closed.
- [x] 【中文用户 & Non English User】请使用英语提交,否则会被关闭 :)
- [x] Please do not modify this template :) and fill in all the required fields.

### Dify version

<=1.17.0

### Cloud or Self Hosted

Self Hosted (Docker)

### Steps to reproduce

Hello Dify maintainers,

I am opening this issue solely to follow up on three private security vulnerability reports that I submitted through GitHub Security Advisories.

The reports are:

GHSA-qwr2-6pr4-pwfv
GHSA-7mj7-x75p-h627
GHSA-5vxc-fmq4-q3qh

It has now been nearly three weeks since the reports were submitted, and I have not received any response or acknowledgement in the private advisory threads.

### ✔️ Expected Behavior

I also sent an email to security@dify.ai approximately one week ago regarding these reports, but I have not received a response there either.

I am creating this public issue only to confirm that the reports have been received and to ask whether they are currently being reviewed.

For security reasons, I will not disclose any vulnerability details, PoCs, or other sensitive information in this public issue. All relevant technical details have already been provided through the private GitHub Security Advisory reports.

I am happy to provide any additional information or reproduction details through the private advisory threads.

Could a Dify maintainer please confirm receipt of these reports and advise whether they are under review?

Thank you.

### ❌ Actual Behavior

_No response_

Contributor guide

Open the contributing guide

Research direction

Start with the three private GitHub Security Advisory reports (GHSA-qwr2-6pr4-pwfv, GHSA-7mj7-x75p-h627, and GHSA-5vxc-fmq4-q3qh) and the security@dify.ai correspondence. This issue is complete when a Dify maintainer confirms receipt and provides a review status through the private advisory threads, without exposing vulnerability details publicly.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.