Re: 🚨 High Risk: Full Source Code Leaked via Exposed .git Repository on https://identity.kde.org

Ben Cooksley bcooksley at kde.org
Wed Sep 30 10:05:57 BST 2026


On Wed, Sep 30, 2026 at 8:16 PM White Hat 127 <xss.payload45 at gmail.com>
wrote:

> Dear Team,
>

Hi there,


> I hope you're doing well. I wanted to follow up on the vulnerability I
> reported. I understand that security assessments and fixes take time, and I
> truly appreciate your team's efforts in addressing these issues.
>
> Please confirm your interest if you are willing to fix the issue to avoid
> further follow-ups. If you have already fixed the issue, kindly let us
> know, and we will proceed with retesting.
>
> As a security researcher, I responsibly reported this vulnerability to
> help secure your platform. In recognition of my efforts, I expect a reward,
> which can be sent via PayPal or bank transfer. I would appreciate an update
> on this discussion as well.
>

Please note that the source code for KDE Identity is publicly visible and
available at https://invent.kde.org/websites/identity-kde-org.
I've now altered our web server configuration though to hide this given it
triggers false positives in scanners such as the one you operate.

As a non-profit open source software project, KDE does not operate a bug
bounty program i'm afraid, but we none the less appreciate security bug
reports (although they should be directed to the appropriate channel -
being our security contacts - not this public mailing list).


> Looking forward to your response.
>
> Best regards
>

Regards,
Ben Cooksley
KDE Sysadmin
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.kde.org/pipermail/kde-www/attachments/20260930/e83be245/attachment.htm>


More information about the kde-www mailing list