🚨 High Risk: Full Source Code Leaked via Exposed .git Repository on https://identity.kde.org

White Hat 127 xss.payload45 at gmail.com
Tue Sep 29 15:43:23 BST 2026





Dear Team,


I hope you're doing well. I wanted to follow up on the vulnerability I reported. 
I understand that security assessments and fixes take time, and I truly appreciate 
your team's efforts in addressing these issues.



Please confirm your interest if you are willing to fix the issue to avoid further follow-ups. 
If you have already fixed the issue, kindly let us know, and we will proceed with retesting.



As a security researcher, I responsibly reported this vulnerability to help secure your platform. 
In recognition of my efforts, I expect a reward, which can be sent via PayPal or bank transfer. 
I would appreciate an update on this discussion as well.



Looking forward to your response.


Best regards


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.kde.org/pipermail/kde-www/attachments/20260929/8fadf80d/attachment.htm>


More information about the kde-www mailing list