Skip to main content
POST
Submit a vulnerability

Authorizations

Authorization
string
header
required

API token generated in the researcher portal under your profile menu, API, Tokens.

Body

application/json
listingId
string
required

Slug of the target, as shown in the target's URL in the researcher portal.

Example:

"k3v9x2mq7d"

title
string
required

Vulnerability title.

Required string length: 1 - 255
description
string
required

What the vulnerability is and where it occurs. Supports Markdown.

Required string length: 10 - 21000
impact
string
required

What an attacker can achieve by exploiting it. Supports Markdown.

Required string length: 10 - 21000

How the customer can remediate it. Supports Markdown.

Required string length: 1 - 22000
cvssVector
string
required

CVSS 3.0, 3.1 or 4.0 base vector. Every base metric is required. The CVSS version and score are calculated from it.

Pattern: ^CVSS:(3\.[01]|4\.0)/
Example:

"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"

exploitableLocations
object[]
required

At most 100,000 characters in total.

Minimum array length: 1
validationSteps
object[]
required

Steps to reproduce the vulnerability. At least one step must include an attachment. At most 25 attachments per step and 50 across all steps.

Required array length: 1 - 50 elements
vulnerabilityCategory
string

Category ID, in the form parent/child. If omitted or other/other, vulnerabilityCategoryOther is used instead.

Example:

"sql_injection/sql_injection"

vulnerabilityCategoryOther
string

Free-text category, used when vulnerabilityCategory is omitted or other/other. Defaults to Not categorized.

Maximum string length: 255
httpRequests
object[]

At most 100,000 characters in total.

collaborations
object[]

Researchers to share the payout with.

Maximum array length: 5
cvesCwes
string[]

CVE and CWE IDs. Duplicates are removed. The combined length of the IDs must not exceed 100 characters.

Example:

Response

The vulnerability was submitted.

vulnerability
object

Vulnerability description.