| title | Security Policy — S4F3-3TCH |
|---|---|
| last_updated | 2026-04-05 |
| Version | Supported |
|---|---|
| 0.1.x | Yes |
If you discover a security vulnerability in S4F3-3TCH, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
- GitHub Security Advisory (preferred): Use GitHub's private vulnerability reporting to submit a confidential report.
- Email: Send details to security@itasha.corp with the subject line
[SECURITY] S4F3-3TCH — <brief description>.
- Description of the vulnerability
- Steps to reproduce
- Affected versions
- Potential impact assessment
- Suggested fix (if any)
| Stage | Timeline |
|---|---|
| Acknowledgement | Within 3 business days |
| Initial assessment | Within 7 business days |
| Fix or mitigation | Within 30 days for critical/high severity |
This policy covers:
- ComfyUI custom node implementations
- Template rendering (Jinja2)
- Input validation and data handling
Out of scope:
- ComfyUI core vulnerabilities (report to ComfyUI maintainers)
- Third-party dependencies (report to their maintainers directly)
- Social engineering attacks