Bounty Triage — Report a vulnerability
Bounty Triageacme · production
Sign in
Program · Submit a report

Report a vulnerability

Reports stay private until coordinated disclosure. You receive a status URL by email and a triager response within five business days.

About the issue

Be specific. We score severity using CVSS 4.0 and pay only for issues we can reproduce.

Severity (your assessment)

A triager will verify with a CVSS 4.0 vector. Your guess does not bind the final payout.

Attachments

PoC videos, request/response captures, screenshots. Up to 5 files · 50 MB each. We scan everything.

Drop files here or choose from your computer
Supported: .png .jpg .mp4 .pdf .txt .har — no executables
poc-ssrf.mp4 — 2.4 MB scanned · clean
validator-response.txt — 6 KB scanned · clean

About you

We never share your contact details outside the triage team.

Shown on the hall of fame and on disclosure pages.
Only used for report-related communication.
You will receive a status URL by email.