open-mmlab / open-mmlab/mmengine

Security contact needed — no SECURITY.md or private reporting channel

Open
#1,697 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
1.5k
Forks
464
PR merge metrics
No merged PRs in 30d

Description

Hi maintainers,

I found what looks like a real security issue in mmengine (unsafe default YAML Loader reachable via mmengine.fileio.load()/Config.fromfile(), including over HTTP via the HTTPBackend). I'd like to report it privately rather than in a public issue, but this repo doesn't have a SECURITY.md and /security/advisories/new isn't available.

Could you either enable GitHub's private vulnerability reporting for this repo, add a SECURITY.md with a contact, or point me to a private channel (e.g. an OpenMMLab security email)? Happy to send full technical details there. Thanks!

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by checking the repository's Security settings and whether SECURITY.md exists. Done means the project has GitHub private vulnerability reporting enabled, or SECURITY.md documents a maintainer-approved private contact channel; the technical vulnerability details should remain private.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.