Third Party Index

Snapshot 48402

Document
Security advisories
URL
https://trust.activepieces.com/?tab=vulnerabilityDisclosure
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
53427 bytes
SHA-256 (raw)
01f4f24aaeffdd0a557514ee0961c5914bcf4d37918d779658b951d2ff414adb
SHA-256 (normalized text)
08fbf1ab82ad888fe64bdae4db6530d0b9f5d35ebd6607dacb555c6d7e876ea9

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Monitored and Powered by
Trust Center
status.activepieces.com
[email protected]
Scope
In scope
Activepieces Cloud: the managed SaaS at cloud.activepieces.com, including the web application and REST API
The Activepieces platform as it runs in Cloud (workflow engine, AI Agents, integration framework, and Tables)
Out of scope
Self-hosted / Community Edition deployments on customer-managed infrastructure. Issues only exploitable in trusted-operator or UNSANDBOXED modes (which are blocked in Cloud) are not in scope.
Customer-connected third-party apps reached through integrations; report those to the respective vendor.
Infrastructure and subservice providers (DigitalOcean, Cloudflare, Hetzner, Google Workspace, and similar); report directly to the provider.
Marketing or website content and third-party platforms we do not operate.
Do not run automated scanners against our infrastructure or dashboard. If you need to scan, contact [email protected] and we will set up a sandbox.
Disclosure Policy
Note: This program is currently private and invitation-only. Reports are welcome from anyone, but reward eligibility is limited to invited researchers at this time.
How to report
Report vulnerabilities privately through the Security tab of our GitHub repository using Report a vulnerability (https://github.com/activepieces/activepieces/security/advisories/new).
Include:
A clear description of the vulnerability and its impact
Steps to reproduce, including the affected URL or endpoint
Any proof-of-concept, logs, or screenshots that help us reproduce it
Rules of engagement
Do not access, modify, or delete data that is not yours; use only what is needed to demonstrate the issue.
Do not run automated scanners against production; contact us for a sandbox.
No denial-of-service, spam, social engineering, or physical attacks.
Keep the report confidential until we have resolved it and coordinated disclosure.
Our commitments
We acknowledge receipt on intake.
We respond within 7 business days with our evaluation (severity and an expected resolution date).
We keep you informed through remediation.
If you follow this policy, we will not pursue legal action against you (safe harbor).
We credit you as the reporter in any published advisory, unless you prefer to remain anonymous.
Disclosure timeline
We follow coordinated disclosure:
We triage and score the report (CVSS 4.0) and confirm severity.
We fix the issue privately and deploy the patch to Cloud.
We notify affected self-managed customers with a lead time before public disclosure.
We publish a security advisory (and CVE where applicable). Default embargo is up to 60 days from the report, shortened if the issue is actively exploited or adjusted by mutual agreement.
We publish advisories only for vulnerabilities that affect users and warrant notification. Whether a report results in a published advisory has no bearing on eligibility for recognition or reward.
Rewards
Rewards are based on the confirmed severity (CVSS 4.0). Final severity and amount are at Activepieces' discretion, considering impact, exploitability, and report quality.
Severity	CVSS 4.0 score	Reward range
Critical	9.0 – 10.0	$1,000 – $4,000
High	7.0 – 8.9	$500 – $1,000
Medium	4.0 – 6.9	$100 – $500
Low	0.1 – 3.9	$50 – $100 or public recognition
Rewards go to the first reporter of a valid, unique, in-scope vulnerability; duplicates and out-of-scope reports are not eligible.
One reward per unique vulnerability; reports sharing a root cause are treated as one, and chained issues are judged on combined impact.
Rewards are discretionary and issued where we are legally permitted to do so.
Note: This vulnerability disclosure program is subject to change. We reserve the right to modify these terms at any time.
Accepted Reports
Vulnerability types we accept
Examples of in-scope vulnerability classes (not exhaustive):
Remote code execution
SQL injection and other server-side injection with a demonstrated sink
Cross-site scripting (XSS) with a demonstrated exploitable sink
Authentication or authorization flaws: broken access control, privilege escalation, IDOR, auth bypass
Server-side request forgery (SSRF)
Exposure of secrets, credentials, or other customers' data
Sensitive data exposure or insecure storage and transmission
CSRF on sensitive, state-changing actions
Security misconfigurations with a demonstrated impact
Not accepted (out of scope)
Clickjacking on pages with no sensitive actions
Unauthenticated / logout / login CSRF
Attacks requiring MITM or physical access to a user's device
Any activity that could disrupt our service (DoS)
Content spoofing or text injection without a demonstrated attack vector
Email spoofing
Missing DNSSEC, CAA, or CSP headers
Lack of Secure or HttpOnly flags on non-sensitive cookies
Dead links
UNSANDBOXED execution mode (intended for trusted-operator deployments; blocked in EE/Cloud production)
Input fields that accept special characters without a demonstrated exploitable sink
Capability-token endpoints (resume URLs, webhook URLs, signed file URLs): the token is the authorization. A report must show a disclosure path (logging, Referer leakage, weak entropy) to be in scope.
Findings whose only attack path is guessing a high-entropy identifier (e.g. nanoid) with no demonstrated disclosure source
Rate-limiting or brute-force issues on unauthenticated endpoints
Vulnerabilities that require a compromised insider
Social engineering, including phishing, against our staff or users
Reflected file download (RFD)
Report a vulnerability
Found a security issue covered by this program? Submit it to Activepieces's security team for review.