We welcome reports of real security vulnerabilities that could affect Amplenote users or our systems. Bounties are only paid for issues that represent a genuine security risk and can be verified by our team. Reports can be sent via email to support@amplenote.com. All reports will be published on this page after they are resolved.
linkWhat Qualifies for a Bounty
A report is eligible for a payout only if all of the following are true:
It describes an actual security vulnerability
The issue is clearly explained with enough detail to test
The vulnerability is reproducible
It affects Amplenote production systems or user data
It is reported in good faith and through responsible disclosure
All reports are reviewed case-by-case. Submitting a report does not guarantee a payout.
linkWhat Does Not Qualify for a Bounty
We do not pay bounties for:
Reports that cannot be reproduced
Reports that do not describe a security issue
General security/standards advice or best-practice suggestions
Theoretical issues with no demonstrable impact
Duplicate or previously reported vulnerabilities
Automated scan output without a proven, working exploit
Issues affecting third-party services, user devices, or out-of-scope systems
Social engineering, phishing, or physical attacks
Cosmetic, UI, or purely informational findings
linkReward Decisions
If a report qualifies, the bounty amount is determined based on:
Severity and impact
How easy the issue is to exploit
Risk to users or data
Whether the report accurately described the issue
All payments are made at our discretion.
linkResponsible Disclosure Rules
By submitting a report, you agree to:
Avoid accessing or altering user data beyond what’s needed to prove the issue
Avoid disrupting service
Not publicly disclose the issue before it is fixed
Give us reasonable time to investigate and respond
Breaking these rules may result in no payout and/or ineligibility for future payouts.
linkLegal Boundaries Still Apply
This program does not give permission to break the law, violate terms of service, or test systems outside scope. All testing must stay within legal and ethical limits.
linkResolved Reports
❌ 08/03/2026 Hyperlink Injection in Profile Name Field
❌ 08/02/2026 Insecure Account Deletion on Amplenote
❌ 07/27/2026 Login Cross-Site Request Forgery (Login CSRF)
❌ 07/27/2024 Change Password Cross-Site Request Forgery (CSRF)
❌ 07/27/2024 Profile Update Cross-Site Request Forgery (CSRF)
❌ 07/24/2026 Change Email Cross-Site Request Forgery (CSRF)
❌ 07/24/2026 Email Enumeration via Login Functionality
❌ 07/23/2026 Null Byte Email Injection in Email Validation
❌ 07/23/2026 Security Report: DNSSEC Not Enabled
❌ 07/23/2026 HTTP Strict Transport Security (HSTS) Not Enforced
❌ 07/23/2026 Missing Cross-Origin-Opener-Policy (COOP) Header
❌ 07/23/2026 Missing Cross-Origin-Embedder-Policy (COEP) Header
☑️ 07/22/2026 Email Enumeration via Registration Page
☑️ 07/06/2026 Sign in with Google compromised
❌ 06/30/2026 Race Condition Allows Multiple Upvotes on Plugins
❌ 06/21/2026 Session Misconfiguration Vulnerability
❌ 04/12/2026 Founder-Level Feature Bypass via API Manipulation
☑️ 04/10/2026 Access Control Bypass via Multi-User Sharing Chain
❌ 04/09/2026 Subscription Bypass via Appearance Manipulation
☑️ 04/09/2026 Improper Permission Handling / Ownership Downgrade
❌ 04/09/2026 Ticket Creation Abuse via Request Replay