If you discover a potential security issue in this project, or believe you may have found a security issue, please notify the ByteDance security team through our security center or vulnerability reporting email. Please do not create a public GitHub issue.
We will assess the vulnerability based on the Common Vulnerability Scoring System (CVSS 3.1). The security team will keep you updated on key progress and may request further information or guidance from you. You are welcome to contact us through the email or website above to ask questions or discuss disclosure matters.
To protect the security of our customers, ByteDance requests that you do not publish or share information regarding the vulnerability in any public forum, or publish or share data involving users, until the vulnerability has been remediated and our users have been notified. The time required for remediation depends on the severity of the vulnerability and the scope of the impact.
Individuals, companies, and security teams may wish to publish security advisories on their own websites or other forums. Please contact us through the email or website above prior to publication to discuss the information that can be disclosed and to coordinate the disclosure timeline.
For information about ByteDance's bug bounty program, visit the ByteDance Security Response Center.