Files
zalo-monitor/_libs/zca-js/.github/ISSUE_TEMPLATE/security.md
T
2026-05-10 22:03:32 +07:00

2.2 KiB

name, about, title, labels, assignees
name about title labels assignees
Security Vulnerability Report Report a security vulnerability [SECURITY] security

Security Vulnerability Report

IMPORTANT: This issue will be handled privately and with the highest priority. Please do not disclose details publicly until the issue is resolved.

Vulnerability Type

  • Authentication bypass
  • Data exposure/information disclosure
  • Code injection
  • Cross-site scripting (XSS)
  • Cross-site request forgery (CSRF)
  • Denial of service (DoS)
  • Privilege escalation
  • Dependency vulnerability
  • Other (please describe)

Severity Level

  • Critical (immediate action required)
  • High (action required within 24 hours)
  • Medium (action required within 1 week)
  • Low (action required within 1 month)

Description

Steps to Reproduce

Expected Behavior

Actual Behavior

Environment

  • zca-js Version:
  • Node.js Version:
  • Operating System:
  • Browser (if applicable):

Impact Assessment

  • Data at Risk:
  • Users Affected:
  • Business Impact:

Suggested Fix

Additional Information

Disclosure Timeline


Note: This report will be reviewed by the security team and handled according to our Security Policy. We appreciate your responsible disclosure and will work to resolve this issue promptly.

⚠️ Warning: This is an unofficial API library. Please ensure your testing does not violate Zalo's terms of service or put any accounts at risk.