[GH-ISSUE #938] Private channel needed to report a potential security issue #3678

Closed
opened 2026-03-13 12:35:53 +03:00 by kerem · 4 comments
Owner

Originally created by @Pundhapat on GitHub (May 24, 2025).
Original GitHub issue: https://github.com/1Remote/1Remote/issues/938

I’ve discovered a potential security issue in 1Remote that I’d like to report privately.
Since the GitHub private vulnerability reporting feature is not enabled for this repository, could you please share the preferred contact method (email address or other process) for submitting security reports?

Originally created by @Pundhapat on GitHub (May 24, 2025). Original GitHub issue: https://github.com/1Remote/1Remote/issues/938 I’ve discovered a potential security issue in 1Remote that I’d like to report privately. Since the GitHub private vulnerability reporting feature is not enabled for this repository, could you please share the preferred contact method (email address or other process) for submitting security reports?
kerem closed this issue 2026-03-13 12:35:58 +03:00
Author
Owner

@VShawn commented on GitHub (May 25, 2025):

Since the GitHub private vulnerability reporting feature is not enabled for this repository, could you please share the preferred contact method (email address or other process) for submitting security reports?

of course you can mail me at: veckshawn@gmail.com

Annnd I will immediately work on enabling the GitHub private vulnerability reporting feature :)

<!-- gh-comment-id:2907647807 --> @VShawn commented on GitHub (May 25, 2025): > Since the GitHub private vulnerability reporting feature is not enabled for this repository, could you please share the preferred contact method (email address or other process) for submitting security reports? of course you can mail me at: veckshawn@gmail.com Annnd I will immediately work on enabling the `GitHub private vulnerability reporting feature` :)
Author
Owner

@Pundhapat commented on GitHub (May 25, 2025):

of course you can mail me at: veckshawn@gmail.com

Thanks for your response. I actually sent an email to that address about a week ago regarding this, but I haven't received a reply. It's possible it might have landed in your spam folder.

I just sent another email to veckshawn@gmail.com a few moments ago, with the subject "Potential Security Vulnerability in 1Remote". Could you please confirm if you received it?

<!-- gh-comment-id:2907663317 --> @Pundhapat commented on GitHub (May 25, 2025): > of course you can mail me at: [veckshawn@gmail.com](mailto:veckshawn@gmail.com) Thanks for your response. I actually sent an email to that address about a week ago regarding this, but I haven't received a reply. It's possible it might have landed in your spam folder. I just sent another email to `veckshawn@gmail.com` a few moments ago, with the subject `"Potential Security Vulnerability in 1Remote"`. Could you please confirm if you received it?
Author
Owner

@VShawn commented on GitHub (May 25, 2025):

Yes, I received the email, but I don't often check my inbox manually, so I didn't see your last message.

For some reason, I haven't been receiving push notifications from Gmail on my phone lately, which led me to believe I hadn't received any emails recently. I only discovered this fact after I manually opened my inbox just now.

Image

P.S. i've enabled the GitHub private vulnerability reporting feature

<!-- gh-comment-id:2907705296 --> @VShawn commented on GitHub (May 25, 2025): Yes, I received the email, but I don't often check my inbox manually, so I didn't see your last message. For some reason, I haven't been receiving push notifications from Gmail on my phone lately, which led me to believe I hadn't received any emails recently. I only discovered this fact after I manually opened my inbox just now. ![Image](https://github.com/user-attachments/assets/5cb4f676-3323-4d26-889b-780c3b726919) P.S. i've enabled the `GitHub private vulnerability reporting feature`
Author
Owner

@Pundhapat commented on GitHub (May 25, 2025):

Thanks for confirming and enabling the GitHub private vulnerability reporting feature. I will proceed to submit the vulnerability through the GitHub private reporting channel.

<!-- gh-comment-id:2907732183 --> @Pundhapat commented on GitHub (May 25, 2025): Thanks for confirming and enabling the GitHub private vulnerability reporting feature. I will proceed to submit the vulnerability through the GitHub private reporting channel.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/1Remote#3678
No description provided.