This repository holds specifications, not running code. That changes where a report should go.
Discuss it in the open. A protocol weakness that nobody can exploit today is exactly what this repository exists to debate, and a public issue or an IPIP puts it in front of the people who can change the spec. Open an issue.
If a deployed system can be attacked today, do not open a public issue here.
Email your report to security@ipfs.io, or use the implementation's own
policy. Kubo, Boxo, Helia and the rest each carry a SECURITY.md.
Include whatever you have: which implementation and version, how to reproduce the problem, and what an attacker gets out of it. A rough report is better than no report, and we will ask if we need more.
A maintainer will confirm we received it and keep you posted while we work on a fix. We are glad to credit you, or to leave you unnamed if you would rather not be credited.
If two weeks pass and no human has replied, assume the message never reached one. Resend it, or escalate: the OpenSSF finder guide lays out the options, and CERT/CC takes reports when coordination with a project breaks down. We would rather you do that than sit on a live bug.
This repository follows the IPFS project security policy.