secvulnerability disclosure
Found a security issue? Tell us.
Thanks for looking out. If you think you’ve found a vulnerability in yoinks. or anything we run, send it our way. We’ll take it seriously, keep you in the loop and credit you if you’d like.
How to report
Email us. One clear report beats several partial ones, but don’t wait to polish it.
hello@yoinks.ioIf the details are sensitive, encrypt them to our public PGP key.
Download pgp.ascgpg --locate-keys hello@yoinks.io
What to include
The more we can reproduce, the sooner we can fix it.
- What’s affected: the URL, file or component.
- Steps to reproduce it, in order.
- What an attacker could do with it, as you understand it.
- A proof of concept, screenshots or logs, if you have them.
- How you’d like to be credited, or that you’d rather not be.
What to expect from us
- 01
We confirm we’ve got it
A real person reads every report and replies to let you know it arrived.
- 02
We look into it
We reproduce the issue, assess the impact and keep you updated as we go.
- 03
We fix it
We tell you when it’s resolved and agree with you on timing before anything is published.
- 04
We say thanks
With your permission, we credit you on this page.
Ground rules
Good-faith research is welcome here. To keep it safe for everyone:
- Only test what you’re allowed to test. If you’re not sure, ask first.
- Don’t access, change or delete data that isn’t yours. If you come across someone else’s data, stop and tell us.
- No denial-of-service, spam, social engineering or physical attacks.
- Use what you find only to confirm the issue, nothing more.
- Give us reasonable time to fix it before sharing details publicly.
Follow these and we’ll treat your report as the help it is, and work with you rather than against you.
Scope
In scope
- yoinks.io and its subdomains.
- Code and tools we publish as ours.
Out of scope
- Third-party services we use. Please report those to the vendor.
- Volumetric denial-of-service.
- Findings with no security impact on their own, such as a missing header.
Thanks
No reports yet. When there are, the people who helped will be listed here, with their permission.