If you discover a security vulnerability, please do not open a public issue or disclose vulnerability details in public discussions, pull requests, logs, or screenshots.
Please report security vulnerabilities through GitHub Private Vulnerability Reporting:
Report a vulnerability privately
If you cannot use GitHub Private Vulnerability Reporting, contact us via email:
Please include the following information when possible:
- The affected ZFile version, component, and deployment method;
- A description of the vulnerability, its impact, and potential risks;
- Reproduction steps, a minimal proof of concept, or relevant sanitized logs;
- Any known mitigations or suggested fixes.
Do not include real passwords, tokens, cookies, private keys, or unnecessary personal data in the report. We will acknowledge the report as soon as possible, assess its impact, and coordinate remediation and disclosure with you. Please avoid public disclosure until a fix is available.
如果你发现了安全漏洞,请勿创建公开 Issue,也不要在公开讨论、Pull Request、日志或截图中披露漏洞细节。
请优先通过 GitHub 私密漏洞报告功能提交:
如果无法使用 GitHub 私密漏洞报告功能,请通过以下邮箱联系我们:
报告时建议包含:
- 受影响的 ZFile 版本、组件和部署方式;
- 漏洞描述、影响范围及潜在风险;
- 可复现步骤、最小化 PoC 或脱敏后的相关日志;
- 已知的缓解措施或修复建议(如有)。
请勿在报告中包含真实密码、Token、Cookie、私钥或不必要的个人数据。我们会尽快确认收到报告、评估影响,并与你协调修复和披露安排。在修复方案发布前,请避免公开漏洞细节。