Request for a Private Security Contact
Hi,
I previously reported a potential SQL injection vulnerability in yudao-cloud through a public GitHub issue. I recently noticed that the issue is deleted.
Could you please confirm whether it was removed intentionally, possibly as part of a private security-reporting process, and let me know the preferred channel for reporting security vulnerabilities?
I am happy to provide the affected version or commit, component details, reproduction steps, impact assessment, and a sanitized proof of concept privately. I will not post exploit details or sensitive request/response data publicly before the issue has been reviewed and, if necessary, fixed.
Additionally, I recommend enabling GitHub’s Security & quality features for this repository, especially Private Vulnerability Reporting, and adding a SECURITY.md file with the preferred vulnerability disclosure process. This would give security researchers a safe way to report issues without exposing sensitive details publicly.
Thank you.
Source: YunaiV/yudao-cloud