Security Report Follow-up — No Response After Nearly Three Weeks
- Dominant language
- TypeScript
- Stars
- 156k
- Forks
- 24.6k
- Avg merge
- 22h 9m
- Merged PRs (30d)
- 610
Description
### Self Checks
- [x] I have read the [Contributing Guide](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) and [Language Policy](https://github.com/langgenius/dify/issues/1542).
- [x] This is only for bug report, if you would like to ask a question, please head to [Discussions](https://github.com/langgenius/dify/discussions/categories/general).
- [x] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify/issues), including closed ones.
- [x] I confirm that I am using English to submit this report, otherwise it will be closed.
- [x] 【中文用户 & Non English User】请使用英语提交,否则会被关闭 :)
- [x] Please do not modify this template :) and fill in all the required fields.
### Dify version
<=1.17.0
### Cloud or Self Hosted
Self Hosted (Docker)
### Steps to reproduce
Hello Dify maintainers,
I am opening this issue solely to follow up on three private security vulnerability reports that I submitted through GitHub Security Advisories.
The reports are:
GHSA-qwr2-6pr4-pwfv
GHSA-7mj7-x75p-h627
GHSA-5vxc-fmq4-q3qh
It has now been nearly three weeks since the reports were submitted, and I have not received any response or acknowledgement in the private advisory threads.
### ✔️ Expected Behavior
I also sent an email to security@dify.ai approximately one week ago regarding these reports, but I have not received a response there either.
I am creating this public issue only to confirm that the reports have been received and to ask whether they are currently being reviewed.
For security reasons, I will not disclose any vulnerability details, PoCs, or other sensitive information in this public issue. All relevant technical details have already been provided through the private GitHub Security Advisory reports.
I am happy to provide any additional information or reproduction details through the private advisory threads.
Could a Dify maintainer please confirm receipt of these reports and advise whether they are under review?
Thank you.
### ❌ Actual Behavior
_No response_
Contributor guide
Research direction
Start with the three private GitHub Security Advisory reports (GHSA-qwr2-6pr4-pwfv, GHSA-7mj7-x75p-h627, and GHSA-5vxc-fmq4-q3qh) and the security@dify.ai correspondence. This issue is complete when a Dify maintainer confirms receipt and provides a review status through the private advisory threads, without exposing vulnerability details publicly.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github
- Domain
- security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100