Skip to content
SECURITY_EXILE

responsible disclosure

This platform is built for hackers, so we expect you to poke at it. If you find a vulnerability, please report it privately so we can fix it before it's abused.

in scope

  • Authorization bypasses on teams, invites, war rooms and writeups
  • XSS / HTML injection via markdown, profiles or comments
  • Spoiler-lock bypasses that reveal writeups before an event ends
  • Invite-code brute forcing or rate-limit bypasses

out of scope

  • Denial of service and volumetric testing
  • Social engineering of members or staff
  • The hidden easter-egg flags. Those are meant to be found.

how to report

See security.txt for the current contact. Please give us reasonable time to fix the issue before disclosing it. We won't pursue action against good-faith research that follows this policy.