Snapshot 48402
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Monitored and Powered by Trust Center status.activepieces.com [email protected] Scope In scope Activepieces Cloud: the managed SaaS at cloud.activepieces.com, including the web application and REST API The Activepieces platform as it runs in Cloud (workflow engine, AI Agents, integration framework, and Tables) Out of scope Self-hosted / Community Edition deployments on customer-managed infrastructure. Issues only exploitable in trusted-operator or UNSANDBOXED modes (which are blocked in Cloud) are not in scope. Customer-connected third-party apps reached through integrations; report those to the respective vendor. Infrastructure and subservice providers (DigitalOcean, Cloudflare, Hetzner, Google Workspace, and similar); report directly to the provider. Marketing or website content and third-party platforms we do not operate. Do not run automated scanners against our infrastructure or dashboard. If you need to scan, contact [email protected] and we will set up a sandbox. Disclosure Policy Note: This program is currently private and invitation-only. Reports are welcome from anyone, but reward eligibility is limited to invited researchers at this time. How to report Report vulnerabilities privately through the Security tab of our GitHub repository using Report a vulnerability (https://github.com/activepieces/activepieces/security/advisories/new). Include: A clear description of the vulnerability and its impact Steps to reproduce, including the affected URL or endpoint Any proof-of-concept, logs, or screenshots that help us reproduce it Rules of engagement Do not access, modify, or delete data that is not yours; use only what is needed to demonstrate the issue. Do not run automated scanners against production; contact us for a sandbox. No denial-of-service, spam, social engineering, or physical attacks. Keep the report confidential until we have resolved it and coordinated disclosure. Our commitments We acknowledge receipt on intake. We respond within 7 business days with our evaluation (severity and an expected resolution date). We keep you informed through remediation. If you follow this policy, we will not pursue legal action against you (safe harbor). We credit you as the reporter in any published advisory, unless you prefer to remain anonymous. Disclosure timeline We follow coordinated disclosure: We triage and score the report (CVSS 4.0) and confirm severity. We fix the issue privately and deploy the patch to Cloud. We notify affected self-managed customers with a lead time before public disclosure. We publish a security advisory (and CVE where applicable). Default embargo is up to 60 days from the report, shortened if the issue is actively exploited or adjusted by mutual agreement. We publish advisories only for vulnerabilities that affect users and warrant notification. Whether a report results in a published advisory has no bearing on eligibility for recognition or reward. Rewards Rewards are based on the confirmed severity (CVSS 4.0). Final severity and amount are at Activepieces' discretion, considering impact, exploitability, and report quality. Severity CVSS 4.0 score Reward range Critical 9.0 – 10.0 $1,000 – $4,000 High 7.0 – 8.9 $500 – $1,000 Medium 4.0 – 6.9 $100 – $500 Low 0.1 – 3.9 $50 – $100 or public recognition Rewards go to the first reporter of a valid, unique, in-scope vulnerability; duplicates and out-of-scope reports are not eligible. One reward per unique vulnerability; reports sharing a root cause are treated as one, and chained issues are judged on combined impact. Rewards are discretionary and issued where we are legally permitted to do so. Note: This vulnerability disclosure program is subject to change. We reserve the right to modify these terms at any time. Accepted Reports Vulnerability types we accept Examples of in-scope vulnerability classes (not exhaustive): Remote code execution SQL injection and other server-side injection with a demonstrated sink Cross-site scripting (XSS) with a demonstrated exploitable sink Authentication or authorization flaws: broken access control, privilege escalation, IDOR, auth bypass Server-side request forgery (SSRF) Exposure of secrets, credentials, or other customers' data Sensitive data exposure or insecure storage and transmission CSRF on sensitive, state-changing actions Security misconfigurations with a demonstrated impact Not accepted (out of scope) Clickjacking on pages with no sensitive actions Unauthenticated / logout / login CSRF Attacks requiring MITM or physical access to a user's device Any activity that could disrupt our service (DoS) Content spoofing or text injection without a demonstrated attack vector Email spoofing Missing DNSSEC, CAA, or CSP headers Lack of Secure or HttpOnly flags on non-sensitive cookies Dead links UNSANDBOXED execution mode (intended for trusted-operator deployments; blocked in EE/Cloud production) Input fields that accept special characters without a demonstrated exploitable sink Capability-token endpoints (resume URLs, webhook URLs, signed file URLs): the token is the authorization. A report must show a disclosure path (logging, Referer leakage, weak entropy) to be in scope. Findings whose only attack path is guessing a high-entropy identifier (e.g. nanoid) with no demonstrated disclosure source Rate-limiting or brute-force issues on unauthenticated endpoints Vulnerabilities that require a compromised insider Social engineering, including phishing, against our staff or users Reflected file download (RFD) Report a vulnerability Found a security issue covered by this program? Submit it to Activepieces's security team for review.