Skip to content

Security: 46b-ETYKiAL/3TCH

Security

SECURITY.md

title Security Policy — S4F3-3TCH
last_updated 2026-04-05

Security Policy

Supported Versions

Version Supported
0.1.x Yes

Reporting a Vulnerability

If you discover a security vulnerability in S4F3-3TCH, please report it responsibly.

Do NOT open a public GitHub issue for security vulnerabilities.

How to Report

  1. GitHub Security Advisory (preferred): Use GitHub's private vulnerability reporting to submit a confidential report.
  2. Email: Send details to security@itasha.corp with the subject line [SECURITY] S4F3-3TCH — <brief description>.

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Affected versions
  • Potential impact assessment
  • Suggested fix (if any)

Response Timeline

Stage Timeline
Acknowledgement Within 3 business days
Initial assessment Within 7 business days
Fix or mitigation Within 30 days for critical/high severity

Scope

This policy covers:

  • ComfyUI custom node implementations
  • Template rendering (Jinja2)
  • Input validation and data handling

Out of scope:

  • ComfyUI core vulnerabilities (report to ComfyUI maintainers)
  • Third-party dependencies (report to their maintainers directly)
  • Social engineering attacks

There aren't any published security advisories