{"id":"5e729209-79a7-4983-864d-8798977a6072","engagementId":"31a31181-8bbb-4eea-a89c-ae5a97879a09","data":{"brief":{"id":"551c9f89-2d78-4775-9edd-de4494900038","name":"Canva","tagline":"Design Anything. Publish Anywhere.","description":"\u003cp\u003eCanva empowers users to design anything and publish anywhere, utilizing our versatile web and mobile apps. Our platform supports both online and physical publishing integrations, offering a wide range of options for your creative projects.\u003c/p\u003e\n\n\u003cp\u003eUsers trust Canva with their personal content, business promotions, product information, media assets, and more. While Canva is available for free, we also offer a Pro subscription that provides access to premium media resources like extensive image libraries. Additionally, our Canva Teams product offers brand kits, digital asset management, and access-control functionality.\u003c/p\u003e\n\n\u003cp\u003eWe prioritize the security of our systems and deeply value the contributions of the security researcher community. Your responsible disclosure of security vulnerabilities is crucial in helping us maintain the security and privacy of our users.\u003c/p\u003e","industryTagId":null,"targetsOverview":"\u003ch2\u003eGuidelines\u003c/h2\u003e\n\n\u003cp\u003eWe require that all researchers:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eProvide a Complete Written Proof-of-Concept\u003c/strong\u003e: Include a detailed description of the vulnerability, steps to reproduce, relevant URLs, and any relevant screenshots or code snippets.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eConduct Ethical Testing\u003c/strong\u003e: Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction of data during security testing.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAdhere to Scope\u003c/strong\u003e: Perform research only within the scope set out below.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eUse Designated Communication Channels\u003c/strong\u003e: Use the identified communication channels to report vulnerability information to us.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eIdentify Yourself\u003c/strong\u003e: Unless required as part of a vulnerability chain, use your @bugcrowdninja.com email address for any test accounts or activities.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eSteps for Submission:\u003c/h3\u003e\n\n\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003eIdentify the Vulnerability\u003c/strong\u003e: Ensure the vulnerability is within the defined scope.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDocument the Vulnerability\u003c/strong\u003e: Provide a detailed description, including steps to reproduce, relevant URLs, and any relevant screenshots or code snippets.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSubmit the Report\u003c/strong\u003e: Use the designated communication channels to submit your report, ensuring you include your @bugcrowdninja.com email address.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003ch2\u003eProhibited Behavior\u003c/h2\u003e\n\n\u003cp\u003eTo ensure the safety of our users, staff, and the Internet at large, you must ensure that your testing does not impact our users in any way. Please use your own accounts for testing and do not access or interact with user data that you do not own.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eOut of Scope Activities\u003c/strong\u003e: e.g. Testing or accessing domains, IP ranges, or systems/services not mentioned in the scope.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eUnauthorized Access and Verification\u003c/strong\u003e: e.g. Using dorking techniques to find and verify credentials belonging to Canva employee personal accounts not related to Canva systems or operations, attempting to log in with credentials found in data breaches, using API keys or cookies that do not belong to you to interact with Canva Services.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePhysical and Social Engineering Attacks\u003c/strong\u003e: e.g. Attempting to gain physical access to our offices or data centers, sending phishing emails to employees to gain access to internal systems, calling employees and pretending to be IT support to extract information.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eService Disruption\u003c/strong\u003e: e.g. Flooding our servers with traffic to cause downtime (DoS/DDoS), exploiting vulnerabilities to intentionally crash services, running automated scripts that generate excessive traffic.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eMalicious Activities\u003c/strong\u003e: e.g. Deploying malware to exploit vulnerabilities, using malicious browser extensions to capture data.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eNoisy and Disruptive Testing\u003c/strong\u003e: e.g. Running automated scripts that generate excessive logs, conducting tests that trigger multiple alerts, using tools that cause noticeable performance degradation.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eData Exfiltration and Privacy Violations\u003c/strong\u003e: e.g. Downloading large amounts of sensitive data, accessing another user's personal information, modifying or deleting user data without permission.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eUnauthorized Disclosure and Interference\u003c/strong\u003e: e.g. Sharing sensitive information found during testing with third parties, tampering with another researcher's test environment or findings, publicly disclosing vulnerabilities without permission.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCredential Stuffing\u003c/strong\u003e: e.g. Using a list of stolen credentials to gain access to user accounts, automating login attempts with known username/password combinations, exploiting password reuse across different services.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePost-Exploitation Lateral Movement\u003c/strong\u003e: e.g. Using Remote Code Execution (RCE) to download source code, performing internal network scanning using Server-Side Request Forgery (SSRF), moving laterally within the network to access additional systems or data.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eAssessing Submissions\u003c/h2\u003e\n\n\u003cp\u003eWe aim to prioritize and address vulnerabilities based on their potential impact. Minor issues will likely be received as informational. We encourage researchers to escalate or chain vulnerabilities to provide a \"proof of concept\" that demonstrates impact.\u003c/p\u003e\n\n\u003cp\u003eFor the initial prioritization and rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases, a vulnerability's priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher, along with the opportunity to appeal and make a case for a higher priority.\u003c/p\u003e\n\n\u003ch3\u003eExamples of Low-Impact Vulnerabilities:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eEmail Server/Relay Misconfiguration\u003c/strong\u003e: Issues such as DMARC/SPF misconfigurations, open relays, or improper email server settings that do not lead to direct security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eClickjacking on Non-Sensitive Actions\u003c/strong\u003e: Clickjacking vulnerabilities that do not lead to sensitive actions or data exposure, such as clickjacking on a non-critical page or button.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eMissing HTTP Security Headers\u003c/strong\u003e: Missing headers such as X-Frame-Options, X-Content-Type-Options, or Content-Security-Policy that do not have a direct security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAutocomplete Enabled on Non-Sensitive Forms\u003c/strong\u003e: Autocomplete enabled on forms that do not handle sensitive information, such as search boxes or non-sensitive user input fields.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eInformation Disclosure in Error Messages\u003c/strong\u003e: Error messages that disclose non-sensitive information, such as internal paths, server names, or stack traces.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eOpen Redirect Resulting in Low Security Impact\u003c/strong\u003e: Open redirect vulnerabilities that do not lead to sensitive data exposure or significant security risks.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eExposed Login Panels Without a PoC\u003c/strong\u003e: Login panels that are exposed but do not have a proof of concept demonstrating a security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eOpen Ports/Services Without a PoC\u003c/strong\u003e: Open ports or services that are identified without a proof of concept demonstrating a security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSSL/TLS Protocol Scan Reports\u003c/strong\u003e: Reports indicating the use of outdated or weak SSL/TLS protocols without demonstrating a practical attack.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eInsecure Cookie Settings for Non-Sensitive Cookies\u003c/strong\u003e: Cookies that lack security attributes (e.g., HttpOnly, Secure) but do not handle sensitive information.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCSRF Without Security Implications\u003c/strong\u003e: Cross-Site Request Forgery vulnerabilities that do not lead to significant security risks or data exposure.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eContent Injection or Content Spoofing\u003c/strong\u003e: Content injection or spoofing vulnerabilities that do not lead to sensitive data exposure or significant security risks.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eVulnerabilities That Cannot Be Used to Exploit Other Users or Canva\u003c/strong\u003e: Issues that do not have a practical impact on other users or the Canva platform.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eLeaking of Other Users' IP Addresses\u003c/strong\u003e: Disclosure of IP addresses that do not lead to significant security risks.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eBest Practice Concerns Without a Demonstrable PoC\u003c/strong\u003e: Issues that are best practice concerns but lack a proof of concept demonstrating a security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCSV Injection Vulnerabilities\u003c/strong\u003e: CSV injection issues that do not lead to significant security risks or data exposure.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eStack Trace\u003c/strong\u003e: Disclosure of stack traces that do not lead to sensitive data exposure or significant security risks.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eExistence of Accounts\u003c/strong\u003e: Identifying the existence of accounts (e.g., submit an email/phone/UUID, get back if it exists) without further impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDisclosure of Non-Sensitive Information\u003c/strong\u003e: Disclosure of non-sensitive information, such as product/framework version, that does not lead to significant security risks.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eID Enumeration Without Any Further Impact\u003c/strong\u003e: Enumeration of IDs (such as user, design, folder, etc.) without any further security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDisclosure of Users' Information That Is Publicly Available\u003c/strong\u003e: Information that is publicly available (e.g., banner grabbing) without leading to significant security risks.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eFunctional, UI, and UX Bugs and Spelling Mistakes\u003c/strong\u003e: Issues related to functionality, user interface, user experience, or spelling that do not have security implications.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eReports Based on Product/Protocol Version Without a Proof of Concept\u003c/strong\u003e: Reports indicating potential issues based on product or protocol versions without a proof of concept demonstrating a security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eIssues Only Affecting Browsers That Canva Does Not Support\u003c/strong\u003e: Issues affecting unsupported browsers (information regarding supported browsers can be found here).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eBrute Force Attacks\u003c/strong\u003e: Brute force attacks that do not lead to significant security risks or data exposure.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSpamming\u003c/strong\u003e: Issues related to spamming that do not lead to significant security risks or data exposure.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eLow Severity Broken Link Hijacking\u003c/strong\u003e: Hijacking links on non-sensitive pages, non-actionable links, internal links that do not lead to external sites, unused social media pages.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAccessing or Downloading Low-Resolution Paid Content Without Payment or Entitlement\u003c/strong\u003e: Issues where users can access or download low-resolution versions of paid content without proper payment or entitlement.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSelf-XSS with No Impact\u003c/strong\u003e: Self-XSS where there is no demonstrable impact to other Canva users.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eRate Limit Bypass\u003c/strong\u003e: It may be possible to bypass rate-limiting on certain endpoints. These will be triaged as P5, except in cases where you are able to bypass OTP/MFA controls or demonstrate security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eBrute Forcing with Partial Random Values\u003c/strong\u003e: Brute forcing where you supply part of a sufficiently random value, such as most of a UUID, in your proof of concept.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eRequiring Attacker-Controlled User-Installed Software\u003c/strong\u003e: Any vulnerability that requires the user to install software or an application from the attacker as part of the attack chain - for example, a specific mobile application, NodeJS package, or desktop application.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAI Jailbreaking, Prompt Leaks, or Prompt Injection\u003c/strong\u003e: Issues involving jailbreaking AIs, leaking prompts, or prompt injection in AI-related features (e.g., Magic Write) are out of scope unless they trigger further vulnerabilities or leak credentials. Inappropriate AI generated content is out of scope and should be reported \u003ca href=\"https://www.canva.com/en_au/help/report-content/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eOur Bug Bounty program should not be used to report content or misconfiguration where the product is working as expected. This includes:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eScamming, Phishing, or Social Engineering Content\u003c/strong\u003e: We receive a large number of reports where Canva is utilized to create or distribute content intended for scamming, phishing, or social engineering purposes. These are not eligible for reward, and can be reported \u003ca href=\"https://www.canva.com/en_au/help/report-content/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eMisconfigurations in Permissions or Access Controls for other Canva Users\u003c/strong\u003e: You may come across misconfigurations related to permissions or access controls for Canva teams or designs belonging to Canva users, including issues with accidental design sharing, exposure of organization join links, and misuse of other sharing features. These are not eligible for reward unless there is a demonstrable security impact to Canva, and can be reported \u003ca href=\"https://www.canva.com/en_au/help/report-content/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eWe are aware of the following issues, and they should not be reported unless a tangible security impact can be demonstrated:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eAccess to Canva Pro Features\u003c/strong\u003e: As a user with a free account, you may be able to access Canva Pro features without a subscription due to client-side access control limitations or insufficient server-side checks.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eNon-Admin Access to Restricted Features\u003c/strong\u003e: As a team admin, you can turn features and functionalities on or off based on your organization's policies and needs. It may be possible for users who are not team admins to access these features or functionalities even when they are restricted by an administrator.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAccess After Removal from Team\u003c/strong\u003e: Following the removal of their account from a team, a Canva user may continue to access resources and certain endpoints for a short period of time.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAdministrator Control Over Member Content\u003c/strong\u003e: It is possible for a team administrator to delete a team member's account and transfer their private designs/content to another account. This is by design. Therefore, attacks from an administrator to a user's private designs/content within a team are considered low severity.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eClient-Side Checks of Permissions\u003c/strong\u003e: Instances where permissions are enforced only on the client side, potentially allowing users to manipulate client-side data to gain unauthorized access to features or resources.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePricing Bypass Methods\u003c/strong\u003e: We are aware of methods where users can bypass standard pricing through specific signup flows or referral links.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eActive Sessions After Password Change\u003c/strong\u003e: Following a password change, cookies for existing user sessions may remain active.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eNo MFA on Social Logins\u003c/strong\u003e: No multi-factor authentication (MFA) is required for social logins for Canva.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eInconsistent API Responses\u003c/strong\u003e: Some APIs may return a 403 or 404 depending on the existence of an underlying object.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSharing a Design Reveals Hidden Content\u003c/strong\u003e: Hidden content within a design, such as notes, hidden pages, and cropped videos, becomes visible to all viewers when a design is shared. This behaviour is noted in our \u003ca href=\"https://www.canva.com/help/share-via-link-or-email/#:%7E:text=Publicly%20sharing%20a%20design\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003epublic documentation\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eDirection for Researchers\u003c/h3\u003e\n\n\u003cp\u003eWe highly value detailed reports that include a clear proof of concept. Demonstrating how a vulnerability can be exploited to cause significant impact will help us prioritize and address the issue more effectively. Reports that lack a demonstrable impact or are based on theoretical scenarios without practical exploitation will be considered low priority.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eExamples of Good vs. Bad Reports:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eGood Report\u003c/strong\u003e: Includes a detailed description of the vulnerability, steps to reproduce, and a proof of concept that demonstrates the potential impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eBad Report\u003c/strong\u003e: Lacks detailed information, does not include steps to reproduce, or fails to demonstrate any significant impact.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eWe appreciate your efforts in helping us improve our security posture. Please ensure that your reports are thorough and provide clear evidence of the vulnerability's impact. This will enable us to address the most critical issues promptly and effectively.\u003c/p\u003e\n\n\u003ch2\u003eGetting Access\u003c/h2\u003e\n\n\u003cp\u003ePlease sign up for an account using your \u003ca href=\"https://researcherdocs.bugcrowd.com/v2.0/docs/your-bugcrowdninja-email-address\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e\u003ccode\u003e@bugcrowdninja.com\u003c/code\u003e email address\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003eYou can further register for the Canva for Work 30 day trial to get full featured access to Canva.\u003c/p\u003e\n\n\u003cp\u003eUsers can also be members of one or more \u003ca href=\"https://www.canva.com/en_au/help/teams-groups/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eteams\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen working as an individual:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDesigns and assets are private to the user, unless the user \u003ca href=\"https://www.canva.com/en_au/help/share-via-link-or-email/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eshares\u003c/a\u003e the design. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen working as part of a team\u003c/strong\u003e:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThere are 4 types of roles a user might assume (Members, Template Designers, Admins and Owners)\u003c/li\u003e\n\u003cli\u003eNotably, Admins and Owners have global read access within the team, and the permissions (though not necessarily the UI) allows them to view and manage designs in the team that are not published to the team yet.\u003c/li\u003e\n\u003c/ul\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":"\u003cp\u003eThis bounty requires explicit permission to disclose the results of a submission\u003c/p\u003e"},"scope":[{"id":"f35e6781-967e-44ba-939b-0bcc2d477446","name":"Canva Editor","targets":[{"id":"01d18729-da5b-44e3-87e7-d99cd3365b2f","uri":"https://www.canva.com","name":"www.canva.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"472b466f-644e-444f-af4d-872b8ed09913","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":2,"description":null,"rewardRange":{"id":"9d1f90ea-c89e-4df9-98aa-be7cab17f630","p1MaxCents":1500000,"p1MinCents":1500000,"p2MaxCents":400000,"p2MinCents":400000,"p3MaxCents":150000,"p3MinCents":150000,"p4MaxCents":20000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eCanva is a powerful design platform that enables users to create, edit, and collaborate on various design projects. Aside from the Canva editor, this target group includes core features such as design sharing, team and organization management, access and feature controls, account settings, AI-powered tools, and digital asset management.\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cp\u003eOur focus for the Canva Editor is simple - keep our user\u0026#39;s data safe, secure, and only accessible by those who should have access. We are particularly interested in vulnerabilities such as:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eServer-Side Vulnerabilities\u003c/strong\u003e: Issues allowing an attacker to execute arbitrary code, perform command or SQL injection, access sensitive data, or disrupt service functionality.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eBroken/Misconfigured Authentication\u003c/strong\u003e: Severe issues that allow attackers to bypass authentication mechanisms, such as session fixation, improper handling of authentication tokens, vulnerabilities in multi-factor authentication, or vulnerabilities in Single Sign-On (SSO) and social identity providers.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eBroken/Misconfigured Authorization\u003c/strong\u003e: Issues allowing an attacker to access unauthorized resources, perform actions beyond their intended permissions, or unintentionally expose sensitive data such as other user designs, personally identifiable information (PII), or data leakage through APIs.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eContent Injection\u003c/strong\u003e: Any content injection vulnerabilities that allow for server or client-side attacks, potentially enabling an attacker to access or disrupt other user accounts.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":15000,"max":15000},"2":{"min":4000,"max":4000},"3":{"min":1500,"max":1500},"4":{"min":200,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"f53ed7a2-aaa2-40ed-8ded-591dc52e5e43","name":"Canva Developer Platform","targets":[{"id":"804e75b0-cf11-40e9-8484-4db62275551c","uri":"https://www.canva.com/developers/","name":"Canva Developer Portal","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"07bd2610-d999-40e1-8fbc-028ba9b2d026","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"59c98214-e03f-497e-8a58-615fb3a14dae","uri":"","name":"Apps SDK Sandboxing","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c7d07239-7feb-4dba-908f-68d23a9a0c52","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"c4ccff3d-63eb-43c1-8973-5be1c6efa9c8","uri":"https://api.canva.com","name":"api.canva.com","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"afba73f9-7ea2-4455-ac08-b602d6b5e33a","sortOrder":2},"sortOrder":2,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"c4ccff3d-63eb-43c1-8973-5be1c6efa9c8"},{"id":"cbf0ee58-c41b-4dee-9d08-cefd01f5d7d6","name":"HTTP","targetId":"c4ccff3d-63eb-43c1-8973-5be1c6efa9c8"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":3,"description":null,"rewardRange":{"id":"9d1f90ea-c89e-4df9-98aa-be7cab17f630","p1MaxCents":1500000,"p1MinCents":1500000,"p2MaxCents":400000,"p2MinCents":400000,"p3MaxCents":150000,"p3MinCents":150000,"p4MaxCents":20000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eThe Canva Developer Platform is designed to empower developers to enhance and expand Canva\u0026#39;s capabilities through using our developer tools - \u003ca href=\"https://www.canva.dev/docs/connect/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eConnect API\u003c/a\u003e and \u003ca href=\"https://www.canva.dev/docs/apps/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eApps SDK\u003c/a\u003e. You can get started by visiting the \u003ca href=\"https://www.canva.com/developers/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eDeveloper Portal\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch3\u003eFocus Areas\u003c/h3\u003e\n\n\u003cp\u003eWe are particularly interested in vulnerabilities that impact the security and isolation of our developer platform tools. Specific areas of interest include:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eBroken Access Control\u003c/strong\u003e: Any method that allows unauthorized access to another developer\u0026#39;s account, integrations, or applications. For example:\n\n\u003cul\u003e\n\u003cli\u003eViewing or modifying another user\u0026#39;s API keys or application settings in the developer portal.\u003c/li\u003e\n\u003cli\u003eBroken access control within the Connect APIs, allowing you to perform IDOR attacks or view/modify data.\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eServer-Side Vulnerabilities\u003c/strong\u003e: Issues such as SQL injection, remote code execution, or other server-side vulnerabilities that could compromise the integrity or availability of the Developer Platform. For example, an endpoint that is vulnerable to SQL injection, allowing an attacker to retrieve or manipulate database contents.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eApps SDK Sandbox Violations\u003c/strong\u003e: We are interested in attacks that violate the security or capability restrictions of our browser-based Apps SDK Sandbox.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eContent Injection\u003c/strong\u003e: Any method that allows unauthorized content to be injected into the Developer Platform tooling, potentially affecting other users. For example, if you can inject malicious scripts into the API documentation or sandbox environment that other users might execute.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eOther Security Vulnerabilities\u003c/strong\u003e: Any other vulnerabilities that impact the security and isolation of our Developer Platform. This includes issues like improper authentication, authorization flaws, or data leakage.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eOut of Scope:\u003c/strong\u003e We are aware of certain issues related to a legacy authentication pattern used by some Canva-branded apps. These may not be eligible for reward if they relate to known patterns currently being phased out. If you\u0026#39;re unsure whether your finding qualifies, please submit it anyway — we will review all submissions individually and provide feedback.\u003c/p\u003e","rewardRangeData":{"1":{"min":15000,"max":15000},"2":{"min":4000,"max":4000},"3":{"min":1500,"max":1500},"4":{"min":200,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"e237a600-67d0-4ef5-b2f0-436c9fd566ea","name":"Canva Services/Infrastructure","targets":[{"id":"1ee4c732-4c88-471a-a473-b2d0b0dd215d","uri":"","name":"*.canva.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ab5fde3a-ceda-4090-ab8f-cd1e75ae7c18","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"1ee4c732-4c88-471a-a473-b2d0b0dd215d"},{"id":"5644ab16-c7ca-4ff7-ac95-383343dab77f","name":"MySQL","targetId":"1ee4c732-4c88-471a-a473-b2d0b0dd215d"},{"id":"6f2f82a5-9ef3-4bc5-9d86-6634e03133e1","name":"Recon","targetId":"1ee4c732-4c88-471a-a473-b2d0b0dd215d"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"1ee4c732-4c88-471a-a473-b2d0b0dd215d"},{"id":"e591e8bc-d7f4-49ad-952f-98dee6c92653","name":"DNS","targetId":"1ee4c732-4c88-471a-a473-b2d0b0dd215d"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"1ee4c732-4c88-471a-a473-b2d0b0dd215d"}],"recentChangeFlags":null},{"id":"cb2fbc58-93b9-4a79-b5de-d2d243bd2021","uri":"","name":"*.canva-apps.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c423c179-b27f-4b47-93e8-e71a27e25499","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"72ada8a6-e110-4468-9209-6cae0a3d0116","uri":"https://*.canva.tech","name":"*.canva.tech","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ee9b16d9-5b3a-4684-aac0-9862d0a5262c","sortOrder":2},"sortOrder":2,"tags":[{"id":"6f2f82a5-9ef3-4bc5-9d86-6634e03133e1","name":"Recon","targetId":"72ada8a6-e110-4468-9209-6cae0a3d0116"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"72ada8a6-e110-4468-9209-6cae0a3d0116"},{"id":"e591e8bc-d7f4-49ad-952f-98dee6c92653","name":"DNS","targetId":"72ada8a6-e110-4468-9209-6cae0a3d0116"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":4,"description":null,"rewardRange":{"id":"9d1f90ea-c89e-4df9-98aa-be7cab17f630","p1MaxCents":1500000,"p1MinCents":1500000,"p2MaxCents":400000,"p2MinCents":400000,"p3MaxCents":150000,"p3MinCents":150000,"p4MaxCents":20000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eThis scope encompasses all web assets and services hosted under the \u003ccode\u003e*.canva.com\u003c/code\u003e domain, as well as any other targets verified as operated by Canva. This includes the various subdomains, APIs, backend services, and other related infrastructure components. Ensuring the security and integrity of these assets is crucial for maintaining the overall security posture of Canva.\u003c/p\u003e\n\n\u003cp\u003etl;dr if you found an issue, and it doesn\u0026#39;t relate to any of the other target groups, please submit it here.\u003c/p\u003e\n\n\u003cp\u003eWe are particularly interested in reports for: \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eServices, APIs, infrastructure, or domains with clear vulnerabilities that allow an attacker access to Canva\u0026#39;s customer data, services, or infrastructure.\u003c/li\u003e\n\u003cli\u003eMisconfigurations in our use of 3rd-party providers, where a tangible security impact can be demonstrated. \n\n\u003cul\u003e\n\u003cli\u003eFor example, overly permissive AWS policies allowing access to our account or substantial Cloudflare misconfigurations.\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eIssues in 3rd-party providers will be assessed according to the \u0026quot;3rd-Party Provider\u0026quot; target group, unless a security issue due to Canva\u0026#39;s misconfiguration can be demonstrated. For example:\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eIn-Scope\u003c/strong\u003e: Canva hosts an AWS Incognito SSO page at example.canva.com which permits sign-ups due to misconfiguration, leading to a vulnerability.\u003cbr\u003e\n\u003cstrong\u003eOut-of-Scope\u003c/strong\u003e: Canva utilizes a 3rd-Party for scheduling on example.canva.com. Their product contains a race condition, leading to multiple appointments being able to be created at the same time.\u003c/p\u003e","rewardRangeData":{"1":{"min":15000,"max":15000},"2":{"min":4000,"max":4000},"3":{"min":1500,"max":1500},"4":{"min":200,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"c2df8a7f-6dfe-42bc-96dc-92a24ad0b9d1","name":"Canva Marketplace Apps \u0026 Integrations","targets":[{"id":"4ef43b12-e84e-4e00-b3c5-f0d82caf1b17","uri":"https://www.canva.com/en_au/help/chatgpt-templates/","name":"Canva for ChatGPT","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2593b2fd-872a-4a8c-80e0-93d0132c4f66","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"05e2c647-8423-47e3-8a4c-884cc8582dae","uri":"https://www.canva.com/integrations/slack/","name":"Canva for Slack","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"eed198aa-a453-48ad-9292-8b2248805d09","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":5,"description":null,"rewardRange":{"id":"0b5bce90-6470-4cdc-87c4-582c4c8a06e9","p1MaxCents":600000,"p1MinCents":600000,"p2MaxCents":150000,"p2MinCents":150000,"p3MaxCents":75000,"p3MinCents":75000,"p4MaxCents":20000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eThe Canva Marketplace Apps \u0026amp; Integrations provide users with the ability to extend Canva\u0026#39;s capabilities by connecting it with other software and services. We are looking for security vulnerabilities within in-scope apps \u0026amp; integrations that could potentially compromise user data, disrupt service functionality, or allow unauthorized access.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eImportant Note\u003c/strong\u003e: Monetary rewards will only be awarded for the applications and integrations listed below. Reports for applications and integrations built by third parties will be forwarded to application developers, and points will be rewarded.\u003c/p\u003e","rewardRangeData":{"1":{"min":6000,"max":6000},"2":{"min":1500,"max":1500},"3":{"min":750,"max":750},"4":{"min":200,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"2ef9239c-78a9-4bd8-9dbe-634c86c3eb42","name":"Canva Native Applications","targets":[{"id":"95ac5f23-1253-4b38-9480-b3e2ceb27a6a","uri":"","name":"Canva Desktop (macOS / Windows)","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"9dd1e16e-0cf3-4070-8c07-6133b5a48aeb","sortOrder":0},"sortOrder":0,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"95ac5f23-1253-4b38-9480-b3e2ceb27a6a"},{"id":"47f8649b-7612-4d6d-bb41-c0078e628292","name":"Electron","targetId":"95ac5f23-1253-4b38-9480-b3e2ceb27a6a"},{"id":"cc05697c-58bf-4b7b-a2b5-2ba0ead3270b","name":"Binary Analysis","targetId":"95ac5f23-1253-4b38-9480-b3e2ceb27a6a"},{"id":"fc8162a2-8e37-4a27-8cbd-3b40e7799f4e","name":"Desktop Application Testing","targetId":"95ac5f23-1253-4b38-9480-b3e2ceb27a6a"}],"recentChangeFlags":null},{"id":"2d452bfc-c54a-4622-9aa3-446699f961fc","uri":null,"name":"Canva (iOS)","category":"ios","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"07bcfa72-5299-4814-a252-7cca806507b0","sortOrder":1},"sortOrder":1,"tags":[{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"2d452bfc-c54a-4622-9aa3-446699f961fc"},{"id":"7692155d-e2db-4c50-abd5-208448a85fde","name":"SwiftUI","targetId":"2d452bfc-c54a-4622-9aa3-446699f961fc"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"2d452bfc-c54a-4622-9aa3-446699f961fc"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"2d452bfc-c54a-4622-9aa3-446699f961fc"},{"id":"cc05697c-58bf-4b7b-a2b5-2ba0ead3270b","name":"Binary Analysis","targetId":"2d452bfc-c54a-4622-9aa3-446699f961fc"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"2d452bfc-c54a-4622-9aa3-446699f961fc"}],"recentChangeFlags":null},{"id":"a1a14cc4-776b-4d48-bde3-b6e3acb950ab","uri":null,"name":"Canva (Android)","category":"android","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"0c9d78ad-e4f0-4f3b-b610-6f033a603394","sortOrder":2},"sortOrder":2,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"a1a14cc4-776b-4d48-bde3-b6e3acb950ab"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"a1a14cc4-776b-4d48-bde3-b6e3acb950ab"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"a1a14cc4-776b-4d48-bde3-b6e3acb950ab"},{"id":"cc05697c-58bf-4b7b-a2b5-2ba0ead3270b","name":"Binary Analysis","targetId":"a1a14cc4-776b-4d48-bde3-b6e3acb950ab"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"a1a14cc4-776b-4d48-bde3-b6e3acb950ab"}],"recentChangeFlags":null},{"id":"f647bc70-7504-4333-8418-870fd94d4ae8","uri":null,"name":"Canva (Chrome Extension)","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"b92ce6d6-db8b-4b24-bc83-b99f18afaada","sortOrder":3},"sortOrder":3,"tags":[{"id":"59791207-9cf4-4498-b5e1-510fee95dc40","name":"Browser Extension","targetId":"f647bc70-7504-4333-8418-870fd94d4ae8"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"f647bc70-7504-4333-8418-870fd94d4ae8"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":6,"description":null,"rewardRange":{"id":"0b5bce90-6470-4cdc-87c4-582c4c8a06e9","p1MaxCents":600000,"p1MinCents":600000,"p2MaxCents":150000,"p2MinCents":150000,"p3MaxCents":75000,"p3MinCents":75000,"p4MaxCents":20000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eThe Canva Native Applications (desktop, mobile, and browser extensions) are designed to provide a seamless and powerful experience for users on their respective devices. We are committed to ensuring the security and integrity of our native apps.\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cp\u003eWe are particularly interested in high-severity vulnerabilities that impact the security and isolation of our native applications. Specific areas of interest include:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eFlaws in Platform-Specific Flows and APIs\u003c/strong\u003e: Vulnerabilities in platform-specific features or APIs that could be exploited to compromise the app\u0026#39;s security. For example, issues with file handling, clipboard access, in-app purchases, biometric authentication, or deep linking that could be abused.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eInsecure Communication\u003c/strong\u003e: Any vulnerability that compromises the security of data in transit, such as lack of encryption (HTTPS) or improper certificate validation. For example, if the app communicates with the server over an unencrypted connection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eSystem/Device Security Violations\u003c/strong\u003e: Any method that violates the security of the system or device, such as unauthorized access to system or device resources (file system, network, hardware, camera, microphone, location) or exploitation of platform-specific vulnerabilities. For example, if an attacker can access sensitive system or device features without user consent.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAuthentication and Authorization Flaws\u003c/strong\u003e: Issues that allow bypassing authentication mechanisms or improper enforcement of user roles and permissions. For example, if an attacker can bypass login or biometric authentication or escalate privileges within the app.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCode Injection and Execution\u003c/strong\u003e: Any method that allows unauthorized code injection or execution within the native applications. For example, if an attacker can inject malicious scripts into the app\u0026#39;s web views or execute arbitrary code.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":6000,"max":6000},"2":{"min":1500,"max":1500},"3":{"min":750,"max":750},"4":{"min":200,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"6aefbb41-3a57-4397-ad38-be3d75b57028","name":"Canva China","targets":[{"id":"d0c5116c-62c1-4326-90e8-af577fd8d6ef","uri":null,"name":"*.canva.cn","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ffc3f4d0-85a2-4e4f-a90f-5b21fcb1fc0f","sortOrder":0},"sortOrder":0,"tags":[{"id":"6f2f82a5-9ef3-4bc5-9d86-6634e03133e1","name":"Recon","targetId":"d0c5116c-62c1-4326-90e8-af577fd8d6ef"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d0c5116c-62c1-4326-90e8-af577fd8d6ef"},{"id":"e591e8bc-d7f4-49ad-952f-98dee6c92653","name":"DNS","targetId":"d0c5116c-62c1-4326-90e8-af577fd8d6ef"}],"recentChangeFlags":null},{"id":"32859d15-f056-49b4-b535-21dd182fc612","uri":"","name":"*.canva-apps.cn","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"13d9ee8f-dc43-419b-ab6a-2e3f36da54ae","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":7,"description":null,"rewardRange":{"id":"9d1f90ea-c89e-4df9-98aa-be7cab17f630","p1MaxCents":1500000,"p1MinCents":1500000,"p2MaxCents":400000,"p2MinCents":400000,"p3MaxCents":150000,"p3MinCents":150000,"p4MaxCents":20000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eCanva China is a localized version of Canva tailored specifically for the Chinese market. It operates under the domain \u003ccode\u003ecanva.cn\u003c/code\u003e and provides the same powerful design tools and features as the global version of Canva, but with adaptations to meet local regulations, user preferences, and market needs. This includes localized content, language support, and integrations with popular Chinese services.\u003c/p\u003e\n\n\u003cp\u003eNetwork configuration findings in \u003ccode\u003e*.canva.cn\u003c/code\u003e are not eligible for a monetary rewards due to network configuration requirements.\u003c/p\u003e","rewardRangeData":{"1":{"min":15000,"max":15000},"2":{"min":4000,"max":4000},"3":{"min":1500,"max":1500},"4":{"min":200,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"b67a6835-48c3-4f16-bfd9-7839d1f379cf","name":"Leaked Credentials and Secrets","targets":[{"id":"0a3312ac-f4f3-4701-87d6-8f9d50999d3d","uri":"","name":"Leaked Credentials and Secrets (Canva Employee/Contractor)","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c6b66d1d-5fd2-4945-8f3a-968c4323dc1a","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"74c90384-9508-42c2-9cbf-677e9b22e2e6","uri":"","name":"Leaked Credentials and Secrets (Canva User)","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e466a14e-b0c3-40bb-916f-3a2bad8d3503","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":8,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eCanva frequently receives reports of datasets containing leaked credentials belonging to Canva employees, contractors, and end-users.\u003c/p\u003e\n\n\u003cp\u003eThese credentials are typically obtained through third-party websites as part of \u0026quot;dumps\u0026quot; or \u0026quot;leaks,\u0026quot; or are made available for purchase. They are often collected by malware, credential stealers, and other malicious software present on end-user devices.\u003c/p\u003e\n\n\u003cp\u003eOccasionally, we may receive reports of secrets, passwords, tokens, or other credentials belonging to Canva employees, contractors, or end-users that have been leaked through developer tooling (e.g., in a GitHub commit).\u003c/p\u003e\n\n\u003cp\u003eThese are either credentials related to a canva.com account, or API keys/secrets belonging to employee/contractor accounts on the services used to develop, build, deploy, and operate Canva.\u003c/p\u003e\n\n\u003cp\u003eUnder no circumstances should suspected credentials be tested. Canva will handle the validation of the supplied credentials and assess their origin and impact.\u003c/p\u003e\n\n\u003cp\u003eWe will not accept reports containing credentials that have been purchased from third parties. We operate tooling to notify us of these listings, and the proceeds from these purchases are often used to fund criminal activities.\u003c/p\u003e\n\n\u003ch3\u003eLeaked Employee/Contractor Credentials and Secrets\u003c/h3\u003e\n\n\u003cp\u003eThese reports will be assessed on a case-by-case basis. Payouts will be determined by the impact of the leaked credentials. It is important to note that Canva uses Okta with Multi-Factor Authentication (MFA), which means that some credentials obtained through malware or credential stealers may not be usable or may only allow access to the MFA prompt page.\u003c/p\u003e\n\n\u003ch3\u003eLeaked User Credentials and Secrets\u003c/h3\u003e\n\n\u003cp\u003eSubmissions disclosing leaked user credentials will only be accepted if the report includes technical details of the vulnerability or misconfiguration within Canva\u0026#39;s systems which led to their disclosure. Valid reports will triaged according to the severity of the vulnerability identified.\u003c/p\u003e\n\n\u003cp\u003eWe will NOT accept reports of leaked customer credentials that are: \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSourced from malware logs, credential stealers, or malicious software on end-user devices \u003c/li\u003e\n\u003cli\u003eFound on OSINT platforms, cybercrime forums, or dark web marketplaces \u003c/li\u003e\n\u003cli\u003ePart of publicly available \u0026quot;combo lists\u0026quot; or credential dumps \u003c/li\u003e\n\u003cli\u003eNot directly tied to a vulnerability in Canva\u0026#39;s products or infrastructure which is disclosed in the same report.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eCanva maintains monitoring systems for detecting compromised credentials from public sources. Reports that do not identify an actual vulnerability will be marked as \u0026#39;Informational\u0026#39; without further action.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"2e04a953-110e-408e-942f-30edb69e1dd7","name":"3rd-Party Providers","targets":[{"id":"67702816-993d-46a8-b9ec-84a976ae9aa1","uri":"","name":"3rd-Party Provider Vulnerability","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"6c49a69c-29a5-4868-b0fa-e5e6b2815cd6","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":9,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eCanva uses a large number of 3rd-party providers. We receive a number of reports where researchers have assessed a product, found an issue, and report these findings to multiple Bug Bounty programs at once as part of the disclosure process.\u003c/p\u003e\n\n\u003cp\u003eResearchers should take care to ensure that they have the provider\u0026#39;s permission to:\u003cbr\u003e\na) perform security testing.\u003cbr\u003e\nb) use their platform to build a proof-of-concept.\u003c/p\u003e\n\n\u003cp\u003eWe will assess vulnerabilities in 3rd-party providers on a case-by-case basis, considering the impact, the role of the provider, what data is stored within the provider, and the tangible and realistic outcomes of such a vulnerability. Due to the number of reports received for 3rd-party provider vulnerabilities, it is highly unlikely that these will be awarded a monetary reward unless a significant security impact or a sophisticated attack chain can be demonstrated.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eVulnerabilities related to BigMarker fall outside the scope of our program. Please report them directly to BigMarker.\u003c/strong\u003e\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"31a31181-8bbb-4eea-a89c-ae5a97879a09","code":"canva","state":"in_progress","endsAt":null,"bountyId":"20372fcb-ec16-4a08-a13e-b2fff4d628d7","startsAt":"2019-01-31T19:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":null,"methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/engagement_brief_logos/engagement_brief/logo/551c9f89-2d78-4775-9edd-de4494900038/8c769045-1a04-4d86-a244-51a48fc7eb76.png","logoBackgroundColor":"#FFFFFF","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2019-01-31T19:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/canva","changelogs":"/engagements/canva/changelog","submissions":null,"announcements":"/engagements/canva/announcements","hallOfFame":"/engagements/canva/hall_of_fames","crowdstream":"/engagements/canva/crowdstream"},"announcementsCount":12,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/canva/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=canva\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/canva/engagement_subscribers","engagementChangelogsUrl":"/engagements/canva/changelog","publishedAt":"2026-08-13T06:17:29.490Z","engagementChangelogUrl":"/engagements/canva/changelog/5e729209-79a7-4983-864d-8798977a6072","createUserFeedbacksUrl":"/engagements/canva/feedbacks","engagementCrowdstreamUrl":"/engagements/canva/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}