Report a bug or vulnerability

Thank you for helping keep our products secure. To be triaged, a report must be reproducible from the information in this form alone. Incomplete, unreproducible, or unverified scanner submissions are closed without review and aren’t eligible for a bounty.

Before you submit, confirm all four:

  1. You tested only assets listed as in-scope in our Vulnerability Disclosure Policy
  2. You used only your own test accounts and accessed no other user’s data
  3. Your report describes what you observed with your own account
  4. You haven’t publicly disclosed this issue

This form is text only. Paste requests, responses, and payloads into the steps; we don’t accept attachments. We acknowledge submissions within 3 business days. Full terms: Vulnerability Disclosure Policy .

What you found

One line: vulnerability type, where, and what it allows. Example: “IDOR on /api/v2/users/{id} allows reading any user’s profile data.”

What the issue is, in plain language.

Select an option

If multiple products are affected, submit a separate report for each one.

Select an option

Choose “Other” rather than forcing a poor fit.

Select an option

Your suggested severity. Our Security team decides the final rating from demonstrated impact.

Optional, e.g. CWE-639. Our team assigns the authoritative mapping during triage.

Optional. A CVSS v3.1 vector string such as AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, not a bare score.

Select an option

Testing against Production is only permitted if explicitly in scope under our Vulnerability Disclosure Policy.

The host or app, the platform, and the exact URLs, API paths, or parameters. One per line.

How to reproduce

Numbered steps from a fresh, logged-out session with exact requests, payloads, and parameter values. Include browser, OS, or SDK version, and anything else the attack needs. If we cannot reproduce the issue from these steps alone, the report is closed as Informational.

Select an option

If the issue needs two separate accounts you control, say so. It materially affects severity.

What an attacker gains, and against whom. Concrete consequences, not theoretical risk.

Your testing

Every test account you used and exactly what data you accessed. Confirm that no data belonging to other users was viewed, copied, or retained.

Select an option

Scanner output you have manually verified and can reproduce is welcome. Unverified scanner output isn’t eligible for a bounty.

Optional: suggested fix, whether this was disclosed anywhere before, whether you’re willing to retest, or how you’d like to be credited.

About you

The name you wish us to correspond under and credit.

Used for all correspondence and bounty coordination. Must match the account visible in your testing.

Read the Vulnerability Disclosure Policy