Skip to content

Commit 6bc9ce4

Browse files
chore: add hyperlink injection in welcome email hall of fame (#2326)
* chore: add hyperlink injection in welcome email hall of fame * Update pages/security/responsible-disclosure.mdx Co-authored-by: ellipsis-dev[bot] <65095814+ellipsis-dev[bot]@users.noreply.github.com> --------- Co-authored-by: ellipsis-dev[bot] <65095814+ellipsis-dev[bot]@users.noreply.github.com>
1 parent c1a0979 commit 6bc9ce4

File tree

1 file changed

+11
-9
lines changed

1 file changed

+11
-9
lines changed

pages/security/responsible-disclosure.mdx

Lines changed: 11 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -33,15 +33,17 @@ Please note that we **currently do not operate a formal bug bounty program** wit
3333

3434
We appreciate the efforts of security researchers who help keep Langfuse secure. The following individuals have responsibly disclosed vulnerabilities that led to improvements:
3535

36-
| Reported by | PR with fix | Description |
37-
| --------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- |
38-
| [Ather Iqbal](https://linkedin.com/in/atheriqbalhacker) | [#4434](https://github.com/langfuse/langfuse/pull/4434) | Password complexity + block links in user name |
39-
| [Milan Jain](https://linkedin.com/in/milan-jain-scriptkiddie-50a738213) | [#6703](https://github.com/langfuse/langfuse/pull/6703) | Hyperlink injection in organization invite email |
40-
| [pyozzi](https://www.linkedin.com/in/sang-yeong-pyo-0411a6207) | [#8821](https://github.com/langfuse/langfuse/pull/8821) | SSRF vulnerability in webhooks |
41-
| [depthfirst](https://www.depthfirst.com) | [#9027](https://github.com/langfuse/langfuse/pull/9027), [#9028](https://github.com/langfuse/langfuse/pull/9028) | Protect background migration endpoints |
42-
| [Carsten Csiky](https://github.com/csicar/) | [#10223](https://github.com/langfuse/langfuse/pull/10223) | Do not expose resolved but blocked IPs in user facing error messages. |
43-
| [Team-DisclosureX Cybrgen](https://linkedin.com/company/cybrgen-limited/), [J Sonali](https://www.linkedin.com/in/j-sonali) | [#10136](https://github.com/langfuse/langfuse/pull/10136), [CVE-2025-64504](https://github.com/langfuse/langfuse/security/advisories/GHSA-94hf-6gqq-pj69) | Cross‑organization enumeration of member & invitation lists via project membership APIs |
44-
| [David Bors at Snyk Security Labs](https://www.linkedin.com/in/davidxbors/) | [#10426](https://github.com/langfuse/langfuse/pull/10426), [GHSA-w9pw-c549-5m6w](https://github.com/langfuse/langfuse/security/advisories/GHSA-w9pw-c549-5m6w) | SSO Account Takeover via CSRF or phishing attack
36+
| Reported by | PR with fix | Description |
37+
|-----------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------|
38+
| [Ather Iqbal](https://linkedin.com/in/atheriqbalhacker) | [#4434](https://github.com/langfuse/langfuse/pull/4434) | Password complexity + block links in user name |
39+
| [Milan Jain](https://linkedin.com/in/milan-jain-scriptkiddie-50a738213) | [#6703](https://github.com/langfuse/langfuse/pull/6703) | Hyperlink injection in organization invite email |
40+
| [pyozzi](https://www.linkedin.com/in/sang-yeong-pyo-0411a6207) | [#8821](https://github.com/langfuse/langfuse/pull/8821) | SSRF vulnerability in webhooks |
41+
| [depthfirst](https://www.depthfirst.com) | [#9027](https://github.com/langfuse/langfuse/pull/9027), [#9028](https://github.com/langfuse/langfuse/pull/9028) | Protect background migration endpoints |
42+
| [Carsten Csiky](https://github.com/csicar/) | [#10223](https://github.com/langfuse/langfuse/pull/10223) | Do not expose resolved but blocked IPs in user facing error messages. |
43+
| [Team-DisclosureX Cybrgen](https://linkedin.com/company/cybrgen-limited/), [J Sonali](https://www.linkedin.com/in/j-sonali) | [#10136](https://github.com/langfuse/langfuse/pull/10136), [CVE-2025-64504](https://github.com/langfuse/langfuse/security/advisories/GHSA-94hf-6gqq-pj69) | Cross‑organization enumeration of member & invitation lists via project membership APIs |
44+
| [David Bors at Snyk Security Labs](https://www.linkedin.com/in/davidxbors/) | [#10426](https://github.com/langfuse/langfuse/pull/10426), [GHSA-w9pw-c549-5m6w](https://github.com/langfuse/langfuse/security/advisories/GHSA-w9pw-c549-5m6w) | SSO Account Takeover via CSRF or phishing attack |
45+
| [Sankalp Tripathi](https://linkedin.com/in/sankalp-tripathi-9bbb982b9) | [#10603](https://github.com/langfuse/langfuse/pull/10603) | Hyperlink injection in welcome email |
46+
4547
## Contact
4648

4749
For all security-related inquiries, including vulnerability disclosures, please contact [email protected].

0 commit comments

Comments
 (0)