Request for a Private Security Contact

Author: CyanM0unCreated Sep 9, 2026Updated Sep 9, 2026

Hi,

I previously reported a potential SQL injection vulnerability in yudao-cloud through a public GitHub issue. I recently noticed that the issue is deleted.

Could you please confirm whether it was removed intentionally, possibly as part of a private security-reporting process, and let me know the preferred channel for reporting security vulnerabilities?

I am happy to provide the affected version or commit, component details, reproduction steps, impact assessment, and a sanitized proof of concept privately. I will not post exploit details or sensitive request/response data publicly before the issue has been reviewed and, if necessary, fixed.

Additionally, I recommend enabling GitHub’s Security & quality features for this repository, especially Private Vulnerability Reporting, and adding a SECURITY.md file with the preferred vulnerability disclosure process. This would give security researchers a safe way to report issues without exposing sensitive details publicly.

Thank you.