How to report a vulnerability
If you've found a security-related issue with Passbolt, please email [email protected]. Do not submit the vulnerability to GitHub as this would make it public and potentially exploitable. We'll do a public disclosure of the security issue once it's been fixed.
What happens after you report
After receiving a report, Passbolt will take the following steps:
- Try first to reproduce the issue and confirm the vulnerability
- Acknowledge to the reporter that we have received the issue and are working on a fix
- Get a fix/patch prepared and create associated automated tests
- Prepare a post describing the vulnerability and the possible exploits
- Release new versions of all affected major versions
- Prominently feature the problem in the release announcement
- Give credit in the release announcement to the reporter if they so desire
What to include in your report
When reporting a vulnerability, please include:
- A clear description of the vulnerability
- Steps to reproduce the issue
- Potential impact of the vulnerability
- Any suggested fixes (if available)
- Your contact information
- The version of Passbolt you tested on
- Any relevant configuration details
Responsible disclosure
We appreciate your help in keeping Passbolt secure. By following responsible disclosure practices, you help us protect our users while we work on a fix. We commit to:
- Acknowledging receipt of your report within 48 hours
- Keeping you informed of our progress
- Giving you credit for your findings (if desired)
- Not taking legal action against you for your research
Bug Bounty Program
Passbolt SA bug bounty program outlines the scope for security researchers and bug bounty hunters working on the Passbolt product. This program is designed to encourage responsible disclosure of security vulnerabilities and improve the overall security of Passbolt.
Rewards
There is currently no financial reward for identified vulnerabilities. However, we highly value your contributions to our platform's security. In recognition of your efforts, we will provide credits acknowledging your discoveries both within our vulnerability reports and across our social media channels.