responsible disclosure
This platform is built for hackers, so we expect you to poke at it. If you find a vulnerability, please report it privately so we can fix it before it's abused.
in scope
- Authorization bypasses on teams, invites, war rooms and writeups
- XSS / HTML injection via markdown, profiles or comments
- Spoiler-lock bypasses that reveal writeups before an event ends
- Invite-code brute forcing or rate-limit bypasses
out of scope
- Denial of service and volumetric testing
- Social engineering of members or staff
- The hidden easter-egg flags. Those are meant to be found.
how to report
See security.txt for the current contact. Please give us reasonable time to fix the issue before disclosing it. We won't pursue action against good-faith research that follows this policy.
