Skip to content

Security reports still untriaged after 9 days despite previous escalation #216

Description

@loopghost

@cedricfung I am opening a new issue because, unfortunately, the situation described in #214 has still not been resolved.

It has now been 9 days since I privately submitted two critical vulnerability reports through GitHub Security Advisories.

After I opened #214, you confirmed publicly that the reports had been received and said:

We have received and will review each reports carefully.

Since too many AI generated reports are submitted these days, it may cause extra time.

I appreciated the confirmation at the time. However, another 5 days have now passed, and neither GHSA has received any response, triage, status update, or even an acknowledgement inside the advisory itself. I have also explicitly asked for an ETA and received no answer.

At this point, I find this extremely concerning.

I completely understand that maintainers may be receiving a large volume of low-quality or AI-generated reports. However, that cannot be an excuse for leaving potentially critical vulnerabilities affecting live systems untouched for 9 days without even communicating a triage timeline to the researcher.

Filtering spam and low-quality submissions is part of operating a vulnerability disclosure or bug bounty process. Legitimate security reports cannot simply disappear into the same queue indefinitely, particularly once their potential severity has been explicitly escalated.

What makes this especially difficult to understand is the disconnect between advertising a bug bounty program with rewards of up to $1,000,000 and the actual experience of trying to responsibly disclose vulnerabilities through it. A program making rewards of that magnitude part of its public security posture should, at an absolute minimum, have a process capable of acknowledging, triaging, and communicating about serious submissions within a reasonable timeframe.

Right now, from a researcher’s perspective, the process feels completely broken. I have spent significant time identifying, validating, documenting, and privately disclosing these issues, yet after 9 days I still have no idea:

  • whether anyone has actually started technically reviewing either of my reports;
  • when triage is expected to happen;
  • who is responsible for handling the reports;
  • or when I should expect any substantive response.

This is also why I am not submitting the additional vulnerability I previously mentioned yet. That issue appears substantially more severe, but producing a rigorous PoC and report requires additional work. Given the handling of the two reports already submitted, I currently have no confidence that investing that additional time makes sense.

I am trying to follow responsible disclosure and get these issues fixed, but responsible disclosure has to work both ways. Researchers cannot reasonably be expected to spend substantial time finding and responsibly reporting serious vulnerabilities while receiving effectively no security-triage communication in return.

I am therefore asking for something very simple and reasonable:

Please provide an actual status update and an ETA for the technical triage of both private GitHub Security Advisories.

I would strongly prefer not to have to keep opening public issues simply to obtain basic communication about privately reported security vulnerabilities.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions