Skip to content

[SECURITY] Critical Vulnerabilities Discovered - Private Disclosure Requested #1029

@JoyGhoshs

Description

@JoyGhoshs

Hello @danpros ,

I have discovered multiple critical security vulnerabilities in HTMLy CMS v3.1.1 that require immediate attention.

Summary (Non-Specific)

  • Severity: Critical
  • Affected Version: v3.1.1
  • Vulnerabilities Found: 3 distinct issues

Responsible Disclosure Attempt

I have attempted to contact you via email 23 days ago with full technical details but have not received a response.

Next Steps

I would like to coordinate responsible disclosure through GitHub Security Advisories:

  1. Please enable Private Vulnerability Reporting on this repository
  2. Or create a Security Advisory and add me as collaborator
  3. Or respond to my email at [your-email]

Timeline

Per industry standards, I am following a 90-day disclosure timeline:

  • First contact: Jan 17, 2026
  • Public disclosure: [DATE - 90 days from first contact]

I prefer coordinated disclosure with patches. Please respond within 7 days to discuss.

Contact

Thank you for maintaining HTMLy. I look forward to working together to protect users.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions