🚨 High Risk: Full Source Code Leaked via Exposed .git Repository on https://identity.kde.org
White Hat 127
xss.payload45 at gmail.com
Tue Sep 29 15:43:23 BST 2026
Dear Team,
I hope you're doing well. I wanted to follow up on the vulnerability I reported.
I understand that security assessments and fixes take time, and I truly appreciate
your team's efforts in addressing these issues.
Please confirm your interest if you are willing to fix the issue to avoid further follow-ups.
If you have already fixed the issue, kindly let us know, and we will proceed with retesting.
As a security researcher, I responsibly reported this vulnerability to help secure your platform.
In recognition of my efforts, I expect a reward, which can be sent via PayPal or bank transfer.
I would appreciate an update on this discussion as well.
Looking forward to your response.
Best regards
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.kde.org/pipermail/kde-www/attachments/20260929/8fadf80d/attachment.htm>
More information about the kde-www
mailing list