#Critical Vulnerability Led to Account Takeover

1 messages · Page 1 of 1 (latest)

vernal mantle
#

Hi team,

I have identified a critical vulnerability that may enable full account takeover. Could you please let me know if you have a bug bounty or responsible disclosure program, and the proper channel to report? @maiden raft

solid blazeBOT
#

Hi @vernal mantle. I'm kapa.ai, your friendly support bot. I will try to answer your question by searching through the knowledge base. :wave:

#

Thank you for reaching out about this important security concern.

The knowledge sources I have access to do not contain any information about a bug bounty program or a formal responsible disclosure policy for Trigger.dev. I cannot confirm or deny whether such a program exists based on the available documentation.

For reporting a critical security vulnerability, I'd recommend reaching out through the following official channels mentioned in the docs:

⚠️ For a critical vulnerability, I would strongly advise not posting details publicly (e.g., in a public GitHub issue or Discord channel) until the team has had a chance to review and address it. Use a private channel or GitHub's private security advisory feature instead.

The Trigger.dev team will be best placed to direct you to the appropriate disclosure process.

Note: you can ask me a follow up question by @ mentioning me again :speech_balloon:

#

@vernal mantle Kapa.ai is still learning and improving, please let me know how I did by reacting below.

vernal mantle
#

@scarlet belfry