{"id":"cf6ad10a-bf27-460c-b1b1-70fb9db15319","engagementId":"13908ee3-00e6-45f6-815c-77e7d4319942","data":{"brief":{"id":"1c049e4e-e7cb-4b8b-b1d6-195ca90d6607","name":"CodeAI","tagline":"Computer Science and AI for every student in every school.","description":"\u003ch1\u003eProgram temporarily paused\u003c/h1\u003e\n\n\u003cp\u003eEffective August 1 at 12:00am Pacific Time, the CodeAI  bug bounty program is temporarily paused while we work through our current submission and remediation backlog and reassess how the program should operate.\u003c/p\u003e\n\n\u003cp\u003eThe engagement is not accepting new bounty submissions during the pause. Reports submitted before the pause took effect will continue to be reviewed under the program terms that applied when they were submitted.\u003c/p\u003e\n\n\u003cp\u003eWe do not yet have a date for resuming the program. We will post an update if and when bounty submissions reopen. Urgent security concerns may still be reported through security@code.org, but reports submitted while the program is paused are not eligible for monetary rewards.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eNOTICE:\u003c/strong\u003e Backlog reports submitted before the pause will be reviewed for technical validity; due to a funding pause, they are not eligible for monetary rewards.\u003c/p\u003e\n\n\u003ch1\u003ePAUSED PROGRAM BRIEF: Welcome to the CodeAI Bug Bounty Program\u003c/h1\u003e\n\n\u003cp\u003eAt CodeAI®, our mission is to give every student access to a world-class computer science education. We appreciate your time and expertise in helping us safeguard that mission. By reporting security issues here, you’re supporting millions of learners—and ensuring student data stays protected.\u003c/p\u003e\n\n\u003ch2\u003eBasic Rules \u0026amp; Best Practices\u003c/h2\u003e\n\n\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003eKeep Findings Confidential:\u003c/strong\u003e Please disclose vulnerabilities only through this platform. Please do not release without our consent.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eBe Considerate of the Environment:\u003c/strong\u003e Use your @bugcrowdninja.com email for test accounts, and steer clear of any testing that might affect legitimate user data or other researchers’ work.  For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eRespect Rate Limits:\u003c/strong\u003e We appreciate your thoroughness, but please avoid overwhelming our systems or performing Denial-of-Service attacks—our test environment is modest.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eStay Within Scope:\u003c/strong\u003e If you discover something on a domain not explicitly listed, we still welcome the report, but it may not qualify for a bounty if it’s marked out-of-scope.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003ch2\u003eOpen Source \u0026amp; Accessibility\u003c/h2\u003e\n\n\u003cp\u003eOur application code is largely \u003ca href=\"https://github.com/code-dot-org/code-dot-org\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eopen source\u003c/a\u003e, so you can dig into our GitHub repository for deeper insight. We also host a publicly accessible \u003ca href=\"https://adhoc-bugcrowd.cdn-code.org/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003etarget environment\u003c/a\u003e, which means you’re free to sign up as different role types (student, teacher, admin, etc.) using your bugcrowdninja.com address. Just remember: no real PII beyond what’s necessary for test accounts, please.\u003c/p\u003e\n\n\u003ch2\u003eCodeAI User Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"https://drive.google.com/file/d/1FbOgFfxeqlNlzLc_6ecPoJjBUF3IszU-/view?usp=drive_link\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eStudents\u003c/a\u003e\u003c/strong\u003e – Minimal PII (hashed email, first name), can join teacher sections and create/share projects.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"https://drive.google.com/file/d/18u6Djnc4_nYcPejmIN75B40Je7WCPvOk/view?usp=drive_link\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eTeachers\u003c/a\u003e\u003c/strong\u003e – Self-chosen by the user at account creation; manage sections, assign work, and set simplified logins for kids.\n\n\u003cul\u003e\n\u003cli\u003eTeachers have limited access to control the log in options for students that have joined their class (section)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eVerified Teacher\u003c/strong\u003e – A teacher marked “verified” by an admin; can bypass throttling; access \u003ca href=\"https://support.code.org/hc/en-us/articles/115001550131-How-to-Become-a-Verified-Teacher\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003econtent not generally available\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eFacilitators/Regional Partners\u003c/strong\u003e – Oversee teacher PD courses but don’t handle student credentials.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAdmins\u003c/strong\u003e – CodeAI staff with elevated privileges (must have \u003ccode\u003e@code.org\u003c/code\u003e email); can assume user identities for support.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eTo minimize sensitive data, we don’t store last names or emails for students.\u003c/p\u003e\n\n\u003ch2\u003eAccount Creation \u0026amp; Login Methods\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eEmail \u0026amp; Password\u003c/strong\u003e – Straightforward sign-in (students’ emails are hashed).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSingle Sign-On (SSO/OAuth)\u003c/strong\u003e – Google, Microsoft, Facebook, Clever, etc.; accounts can link multiple providers.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"https://drive.google.com/file/d/18u6Djnc4_nYcPejmIN75B40Je7WCPvOk/view?usp=drive_link\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eTeacher-Created Accounts\u003c/a\u003e\u003c/strong\u003e – Teachers provide a 6-letter section code (no personal email required).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSimple Logins\u003c/strong\u003e – \u003ca href=\"https://drive.google.com/file/d/1Rp-UYzx8ePXoB2U5txq9sMOat1O1M3f1/view?usp=drive_link\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ePicture choice\u003c/a\u003e or two-word phrase for younger students.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eFederation (External Tools)\u003c/strong\u003e – Automatic creation/login via Google Classroom, Schoology, LTI, etc.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eWe recommend you make separate “teacher” and “student” logins using \u003cstrong\u003e\u003ccode\u003e[username]+teacher@bugcrowdninja.com\u003c/code\u003e\u003c/strong\u003e and \u003cstrong\u003e\u003ccode\u003e[username]+student@bugcrowdninja.com\u003c/code\u003e\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch2\u003eThings that Users Own\u003c/h2\u003e\n\n\u003ch3\u003eStudent Coding Projects\u003c/h3\u003e\n\n\u003cp\u003eWe offer various “Labs” tailored for different programming experiences.  Students can create projects using labs like these:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003ca href=\"https://drive.google.com/file/d/1lfOVZoXkwsdRqSvxm6SNukIS6_grGJqU/view?usp=drive_link\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e\u003cstrong\u003eBlock-Based Labs\u003c/strong\u003e\u003c/a\u003e (Sprite Lab, Flappy, Minecraft, Frozen, Dance Party): Intro to coding via drag-and-drop blocks.\u003c/li\u003e\n\u003cli\u003e\n\u003ca href=\"https://drive.google.com/file/d/15Nb71v2cxU1lOFYX4SZetZFxXNpLTfaF/view?usp=drive_link\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e\u003cstrong\u003eApp Lab\u003c/strong\u003e\u003c/a\u003e and \u003ca href=\"https://drive.google.com/file/d/1c6584V5b3S0xLl9TyksDyfJWuWZv4iBF/view?usp=drive_link\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e\u003cstrong\u003eGame Lab\u003c/strong\u003e\u003c/a\u003e: More advanced, allowing JavaScript coding and game creation.\u003c/li\u003e\n\u003cli\u003e\n\u003ca href=\"https://drive.google.com/file/d/1pnK6I3zsZAm4PvKbsBwdagVur3dIIoOz/view?usp=drive_link\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e\u003cstrong\u003eWeb Lab\u003c/strong\u003e\u003c/a\u003e: Lets students build and host HTML/CSS projects.\u003c/li\u003e\n\u003cli\u003e🎉 \u003ca href=\"https://code.org/en-US/tools/python-lab\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e\u003cstrong\u003ePython Lab\u003c/strong\u003e\u003c/a\u003e: Our new lab type, executing Python in the web browser.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eJava Lab\u003c/strong\u003e, \u003cstrong\u003eAI Lab\u003c/strong\u003e, and Others: Specialized experiences for Java, AI experiments, and a variety of legacy labs.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eStudents should be the only ones allowed to edit their project.  However, most labs are automatically shared, if someone knows the link.  Our share functions only make it easier to share the existing public link.  Visitors see a read-only version of the project and can “remix”.\u003c/p\u003e\n\n\u003ch3\u003eCurriculum\u003c/h3\u003e\n\n\u003cp\u003eCurriculum can be accessed in one of two ways:\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eTeachers assign curriculum to students (and when the student logs in, they are \u003ca href=\"https://drive.google.com/file/d/1Rp-UYzx8ePXoB2U5txq9sMOat1O1M3f1/view?usp=drive_link\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eimmediately taken there\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStudents can directly \u003ca href=\"https://drive.google.com/file/d/1eeGSc08ATwL7EvUlKJDVi5bXuuLvngOO/view?usp=drive_link\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ebrowse the Course Catalog\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003eCurriculum “levels” are units of educational content that behave similarly to Projects. They save the student’s work, but these do not have the sharing functions that projects do.  There are various other variations in the curriculum level experience, to instruct and measure progress\u003c/p\u003e","industryTagId":"f2d64fa8-5daf-49ef-8de8-edc7da2dfb4a","targetsOverview":"\u003ch2\u003eTarget Platform Caveats\u003c/h2\u003e\n\n\u003cp\u003eOur Target environment varies from our Production Environment in the following known aspects:\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eWebLab: there is no way to see the visiting-user view (codeprojects.org)\u003c/li\u003e\n\u003cli\u003eFederated Logins: you cannot log in via Google, Microsoft, Facebook, Clever or any LTI paths\u003c/li\u003e\n\u003cli\u003eCourse Catalog: Some links go direct to production (see workaround in \u003ca href=\"https://drive.google.com/file/d/1eeGSc08ATwL7EvUlKJDVi5bXuuLvngOO/view\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ethis video\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eThe environment will go down for 15-25 minutes each time it updates to the new version (auto-updates when we deploy to production).  We don't have the same graceful autoscaler and deploy mechanism that we do in production, so restarting the target environment's web server is a necessary step today.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through this program, or inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"320e7e23-f84d-4db0-93b5-3f67f4160b9d","name":"In Scope Targets","targets":[{"id":"d430c0fe-2842-4fa6-925d-444151af81f8","uri":"https://adhoc-bugcrowd.cdn-code.org","name":"adhoc-bugcrowd.cdn-code.org","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"842e1633-a223-4bb7-8eaf-839a2a95e900","sortOrder":0},"sortOrder":0,"tags":[{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"d430c0fe-2842-4fa6-925d-444151af81f8"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"d430c0fe-2842-4fa6-925d-444151af81f8"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"d430c0fe-2842-4fa6-925d-444151af81f8"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d430c0fe-2842-4fa6-925d-444151af81f8"}],"recentChangeFlags":null},{"id":"91712e3d-5d5b-405b-aac1-316b21641221","uri":"https://adhoc-bugcrowd-studio.cdn-code.org","name":"adhoc-bugcrowd-studio.cdn-code.org","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d16ed8f6-9ba5-497f-a316-0dcb513aeed8","sortOrder":0},"sortOrder":0,"tags":[{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"91712e3d-5d5b-405b-aac1-316b21641221"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"91712e3d-5d5b-405b-aac1-316b21641221"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"91712e3d-5d5b-405b-aac1-316b21641221"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"91712e3d-5d5b-405b-aac1-316b21641221"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null},{"id":"808fa5f7-4811-4a40-9bc0-c1ed45964120","name":"Out of scope","targets":[{"id":"e356ec9f-5677-4ece-8a45-88b25f07cbf8","uri":"https://hourofcode.com","name":"hourofcode.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"3ebd05d4-d455-4b6d-a007-0b473e2f1ca9","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"e356ec9f-5677-4ece-8a45-88b25f07cbf8"}],"recentChangeFlags":null},{"id":"a0596a01-c92e-4179-969e-5b75823a6f15","uri":null,"name":"advocacy.code.org","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"515c54e7-d5d2-4e49-b47b-df546b2c67f0","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a0596a01-c92e-4179-969e-5b75823a6f15"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"13908ee3-00e6-45f6-815c-77e7d4319942","code":"codeorg","state":"in_progress","endsAt":null,"bountyId":"7155f7f7-0312-4546-ad75-e8cdca0c0c0f","startsAt":"2019-02-14T19:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Education","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/a125/0488/08dd1086/dcf2a67061c95bfffb397362e2668fff_code_image.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2019-02-14T19:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/codeorg","changelogs":"/engagements/codeorg/changelog","submissions":null,"announcements":"/engagements/codeorg/announcements","hallOfFame":"/engagements/codeorg/hall_of_fames","crowdstream":"/engagements/codeorg/crowdstream"},"announcementsCount":22,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/codeorg/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=codeorg\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/codeorg/engagement_subscribers","engagementChangelogsUrl":"/engagements/codeorg/changelog","publishedAt":"2026-08-27T21:52:58.145Z","engagementChangelogUrl":"/engagements/codeorg/changelog/cf6ad10a-bf27-460c-b1b1-70fb9db15319","createUserFeedbacksUrl":"/engagements/codeorg/feedbacks","engagementCrowdstreamUrl":"/engagements/codeorg/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}