{"id":"693fa647-f03e-4cd2-aa47-aaa66c3e3a9f","engagementId":"ea4aeb97-3ade-4347-bfed-65fe221049b0","data":{"brief":{"id":"489e3168-35aa-4b97-8dd9-b75349c3a4a9","name":"Home Depot Vulnerability Disclosure Engagement","tagline":"Make doing work for you.","description":"\u003cp\u003eThe Home Depot, the world’s largest home improvement specialty retailer, values and rewards dedicated, knowledgeable, and experienced professionals. We operate more than 2,300 retail stores in all 50 states, the District of Columbia, Puerto Rico, the U.S. Virgin Islands, Guam, Canada, and Mexico. All of our associates have one thing in mind — helping our customers build and improve their homes. Join The Home Depot team today and see for yourself why we are consistently ranked as a top Fortune 500 company.\u003c/p\u003e\n\n\u003ch2\u003eRatings\u003c/h2\u003e\n\n\u003cp\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/p\u003e","industryTagId":"9ed1ce49-a148-438f-92d3-0b8d70b6a8ae","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Home Depot not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to this engagement, you can report it to this engagement. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eEngagement Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe do not accept reports that contain low-effort or AI-generated content. Submissions must demonstrate original analysis, clear understanding of the issue, and actionable detail. Reports lacking meaningful human input will be rejected\u003c/li\u003e\n\u003cli\u003eResearchers must throttle all testing activity to avoid degrading service availability, triggering automated defenses, or negatively impacting other users. Excessive request rates, high-volume scanning, denial-of-service techniques, or other disruptive testing methods are prohibited\u003c/li\u003e\n\u003cli\u003ePotential post-exploitation scenarios: If you believe you've identified a vulnerability that may lead to post-exploitation activity including modification or destruction of data please stop testing and submit your finding. We will work with you to evaluate the vulnerability and award you accordingly for the final impact and severity\u003c/li\u003e\n\u003cli\u003eYou are testing on production. Behavior that compromises the stability and integrity of the target(s) is out of scope\n\n\u003cul\u003e\n\u003cli\u003eFor example, do not target other users' data (use one of your other sets of credentials), delete/remove/edit parts of the site, engage any sort of DoS attack, and/or compromise any target's ability to function for other users. If you believe that you have found a vulnerability of this nature, please stop further testing and report it\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eReport Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities discovered on multiple paths, endpoints, parameters will be treated as duplicates. This includes findings across different environments (e.g., development, staging, production) unless the impact or exploitation method is materially different. Please submit only one report\u003c/li\u003e\n\u003cli\u003eReports must contain the security impact along with detailed steps to reproduce it. If the issue cannot be reliably reproduced based on your report, it may not be accepted.\u003c/li\u003e\n\u003cli\u003eReports based only on automated tool/scanner results or which describe theoretical attack vectors without proof of exploitability will not be accepted\u003c/li\u003e\n\u003cli\u003eDo not submit more than one vulnerability per report. In cases where demonstrating impact requires chaining multiple vulnerabilities together, those can be included in the same report as long as the linkage is clearly explained\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess\u003c/h2\u003e\n\n\u003cp\u003eThe target app is publicy accessible.\u003c/p\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eCredentials are not required nor provided for testing. However, where possible you may create an account for testing using your @bugcrowdninja email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eAny third party integration is considered out of scope.\u003c/strong\u003e \u003c/p\u003e\n\n\u003cp\u003eOut of scope vulnerabilities or testing methodologies include:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNo Denial-of-Service testing\u003c/li\u003e\n\u003cli\u003eNo Physical or Social Engineering\u003c/li\u003e\n\u003cli\u003eNo testing of Third-party Services\u003c/li\u003e\n\u003cli\u003eNo uploading of any vulnerability or client-related content to third-party utilities (e.g. Github, DropBox, YouTube)\u003c/li\u003e\n\u003cli\u003eAll attack payload data must use professional language\u003c/li\u003e\n\u003cli\u003eIf able to gain access to a system, accounts, users, or user data, stop at point of recognition and report. Do not dive deeper to determine how much more is accessible.\u003c/li\u003e\n\u003cli\u003eWhen documenting a vulnerability, if a vulnerability is public, please make sure it is discreet and doesn't identify the client.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eThe following vulnerabilities are considered too low of an impact to the client and would be marked as Out of Scope if submitted:\u003c/em\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eGoogle Maps API Keys\u003c/li\u003e\n\u003cli\u003eAccount/e-mail enumeration using brute-force attacks\n\n\u003cul\u003e\n\u003cli\u003eValid user account/email enumeration not requiring brute-force will be considered\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAny low impact issues related to session management (i.e. concurrent sessions, session expiration, password reset/change log out, etc.)\u003c/li\u003e\n\u003cli\u003eBypassing content restrictions in uploading a file without proving the file was received\u003c/li\u003e\n\u003cli\u003eClickjacking/UI redressing\u003c/li\u003e\n\u003cli\u003eClient-side application/browser autocomplete or saved password/credentials\u003c/li\u003e\n\u003cli\u003eDescriptive or verbose error pages without proof of exploitability or obtaining sensitive information\u003c/li\u003e\n\u003cli\u003eDirectory structure enumeration (unless the fact reveals exceptionally useful information)\u003c/li\u003e\n\u003cli\u003eIncomplete or missing SPF/DMARC/DKIM records\u003c/li\u003e\n\u003cli\u003eIssues related to password/credential strength, length, lockouts, or lack of brute-force/rate-limiting protections\n\n\u003cul\u003e\n\u003cli\u003eAccount compromises (especially admin) as a result of these issues will likely be considered VALID\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eLack of SSL or Mixed content\n\n\u003cul\u003e\n\u003cli\u003eLeaking Session Cookies, User Credentials, or other sensitive data will be reviewed on a case by case basis\u003c/li\u003e\n\u003cli\u003eIf leaking of sensitive data requires MiTM positioning to exploit, it will be considered out of scope\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eLogin/Logout/Unauthenticated/Low-impact CSRF\n\n\u003cul\u003e\n\u003cli\u003eCSRF Vulnerabilities may be acceptable if they are of higher impact. Examples of low impact CSRF include: Add/Delete from Cart, Add/remove wishlist/favorites, Nonsevere preference options, etc.\u003c/li\u003e\n\u003cli\u003eLow impact Information disclosures (including Software version disclosure)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eMissing Cookie flags\u003c/li\u003e\n\u003cli\u003eMissing/Enabled HTTP Headers/Methods which do not lead directly to a security vulnerability\u003c/li\u003e\n\u003cli\u003eReflected file download attacks (RFD)\u003c/li\u003e\n\u003cli\u003eSelf-exploitation (i.e. password reset links or cookie reuse)\u003c/li\u003e\n\u003cli\u003eSSL/TLS best practices that do not contain a fully functional proof of concept\u003c/li\u003e\n\u003cli\u003eURL/Open Redirection\u003c/li\u003e\n\u003cli\u003eUse of a known-vulnerable library which leads to a low-impact vulnerability (i.e. jQuery outdated version leads to low impact XSS)\u003c/li\u003e\n\u003cli\u003eValid bugs or best practice issues that are not directly related to the security posture of the client\u003c/li\u003e\n\u003cli\u003eVulnerabilities affecting users of outdated browsers, plugins or platforms\u003c/li\u003e\n\u003cli\u003eVulnerabilities that allow for the injection of arbitrary text without allowing for hyperlinks, HTML, or JavaScript code to be injected\u003c/li\u003e\n\u003cli\u003eVulnerabilities that require the user/victim to perform extremely unlikely actions (i.e. Self-XSS)\n\n\u003cul\u003e\n\u003cli\u003eSelf-XSS for a Persistent/Stored XSS will be considered. Please review the Self-XSS article for more information.\u003c/li\u003e\n\u003cli\u003eAny type of XSS that requires a victim to press an unlikely key combination is NOT in scope (i.e. alt+shift+x for payload execution)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eAdditional specific vulnerability types considered out of scope due to low impact:\u003c/em\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eIIS Tilde File and Directory Disclosure\u003c/li\u003e\n\u003cli\u003eSSH Username Enumeration\u003c/li\u003e\n\u003cli\u003eWordpress Username Enumeration\u003c/li\u003e\n\u003cli\u003eSSL Weak Ciphers/ POODLE / Heartbleed\u003c/li\u003e\n\u003cli\u003eCSV Injection\u003c/li\u003e\n\u003cli\u003ePHP Info\u003c/li\u003e\n\u003cli\u003eServer-Status if it does not reveal sensitive information\u003c/li\u003e\n\u003cli\u003eSnoop Info Disclosures\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our \u003ca href=\"https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eTerms \u0026amp; Conditions\u003c/a\u003e  that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via our \u003ca href=\"https://bugcrowd-support.freshdesk.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eFreshdesk Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"40e5a539-fcc2-42d2-9d46-c85eb7f44961","name":"In Scope","targets":[{"id":"f52be6a3-a222-4189-b287-2cd8af4fb94c","uri":null,"name":"*.homedepot.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c6130a9b-f6a0-4cef-9278-2a745e9f5e03","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"f52be6a3-a222-4189-b287-2cd8af4fb94c"},{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"f52be6a3-a222-4189-b287-2cd8af4fb94c"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"f52be6a3-a222-4189-b287-2cd8af4fb94c"},{"id":"e4ad1c44-2f86-487b-9793-0add0dbfdcf2","name":"Zone.js","targetId":"f52be6a3-a222-4189-b287-2cd8af4fb94c"},{"id":"eaa69542-87cd-413a-9b74-3e75f9fb01e4","name":"Angular","targetId":"f52be6a3-a222-4189-b287-2cd8af4fb94c"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"f52be6a3-a222-4189-b287-2cd8af4fb94c"}],"recentChangeFlags":null},{"id":"cc5bfeb2-85bd-4b60-9822-8f51cb13272f","uri":null,"name":"*.homedepot.com.mx","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4c9a37df-3129-4817-a709-f5355225f3f1","sortOrder":1},"sortOrder":1,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"cc5bfeb2-85bd-4b60-9822-8f51cb13272f"},{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"cc5bfeb2-85bd-4b60-9822-8f51cb13272f"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"cc5bfeb2-85bd-4b60-9822-8f51cb13272f"},{"id":"e4ad1c44-2f86-487b-9793-0add0dbfdcf2","name":"Zone.js","targetId":"cc5bfeb2-85bd-4b60-9822-8f51cb13272f"},{"id":"eaa69542-87cd-413a-9b74-3e75f9fb01e4","name":"Angular","targetId":"cc5bfeb2-85bd-4b60-9822-8f51cb13272f"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"cc5bfeb2-85bd-4b60-9822-8f51cb13272f"}],"recentChangeFlags":null},{"id":"e10b294e-903e-4e67-a9ee-f0d2801fe8cf","uri":null,"name":"*.homedepot.ca","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"6466b09b-20c7-4527-aaf3-6a8320dfb651","sortOrder":2},"sortOrder":2,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"e10b294e-903e-4e67-a9ee-f0d2801fe8cf"},{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"e10b294e-903e-4e67-a9ee-f0d2801fe8cf"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"e10b294e-903e-4e67-a9ee-f0d2801fe8cf"},{"id":"e4ad1c44-2f86-487b-9793-0add0dbfdcf2","name":"Zone.js","targetId":"e10b294e-903e-4e67-a9ee-f0d2801fe8cf"},{"id":"eaa69542-87cd-413a-9b74-3e75f9fb01e4","name":"Angular","targetId":"e10b294e-903e-4e67-a9ee-f0d2801fe8cf"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"e10b294e-903e-4e67-a9ee-f0d2801fe8cf"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null},{"id":"7aa7ee8b-72a1-4c4d-8d07-79a177bcb161","name":"Out of Scope ","targets":[{"id":"ec4f2251-2030-466c-a28d-a1ff04bd9453","uri":"","name":"ecooptions.homedepot.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"fe3871d2-6392-4abc-9585-6fe940bb33bb","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"b8506a6e-ab15-4d66-910e-8d974615b657","uri":"","name":"ir.homedepot.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a76e9e5c-45e3-4bad-8cd4-9cd7ce610f93","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"8548915f-3eab-43fe-9f60-87e89d4ef43c","uri":"","name":"corporate.homedepot.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2e9108ee-a59e-4492-919d-9f3b3decdbe7","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null},{"id":"2c5cb22a-7e54-4411-a205-c020524a1480","uri":"","name":"www.thecompanystore.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f4f72393-56ba-4229-ab9d-7a41fb24fce6","sortOrder":3},"sortOrder":3,"tags":null,"recentChangeFlags":null},{"id":"489d3e7a-bfcc-41ac-a60e-6f3420ce7d11","uri":"","name":"www.proreferral.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"0ed0033d-4b84-4044-a16b-4b2a65960d7d","sortOrder":4},"sortOrder":4,"tags":null,"recentChangeFlags":null},{"id":"fefba677-eeb4-4974-8ed8-3265f134e861","uri":"","name":"www.blinds.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a4e68ca4-308c-436c-87da-da70f086c34f","sortOrder":5},"sortOrder":5,"tags":null,"recentChangeFlags":null},{"id":"055bcd1c-dba7-4f75-ac5a-5f18eda4b230","uri":"","name":"homedepot.egifter.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3851e4c1-a7f7-423f-9d01-fc221bdd9389","sortOrder":6},"sortOrder":6,"tags":null,"recentChangeFlags":null},{"id":"61340515-1440-4583-b86f-181ad8514385","uri":"","name":"homedepot.cashstar.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"10a2fcd6-b49f-458c-8691-806e42ef0714","sortOrder":7},"sortOrder":7,"tags":null,"recentChangeFlags":null},{"id":"bd69d200-574a-4070-a5e0-60360f20cc73","uri":"","name":"hdmoving.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"078f54ef-1c68-4189-ad82-09acd433cb44","sortOrder":8},"sortOrder":8,"tags":null,"recentChangeFlags":null},{"id":"18c27dae-36e3-4780-93aa-1e34c29c6f5e","uri":"","name":"thdloan.greenskycredit.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"0f72c238-7418-4f36-8cda-689ff53bed37","sortOrder":9},"sortOrder":9,"tags":null,"recentChangeFlags":null},{"id":"4a37b55f-5c78-40d4-afeb-ce9d1aee55ac","uri":"","name":"www.thdloanonline.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"26dc37fc-0f5c-44b9-9d16-0059b0540979","sortOrder":10},"sortOrder":10,"tags":null,"recentChangeFlags":null},{"id":"3c551fc8-9ba4-4210-9d18-c423b12f97b8","uri":"","name":"citiretailservices.citibankonline.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"eb5acf27-72da-466c-8f53-705e34ef9c89","sortOrder":11},"sortOrder":11,"tags":null,"recentChangeFlags":null},{"id":"a989ed65-d871-477a-82af-b9002b78d6a0","uri":"","name":"www.retailservicescommercial.citi.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"707ea2da-e33b-43b7-8258-710dd6088ebd","sortOrder":12},"sortOrder":12,"tags":null,"recentChangeFlags":null},{"id":"49a08e6b-3419-4175-8dfe-ee383dc82339","uri":"","name":"refacing.homedepot.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a67630a3-ed6d-44ae-bbf9-c5194cf82f48","sortOrder":13},"sortOrder":13,"tags":null,"recentChangeFlags":null},{"id":"aea0b76f-e412-4f20-b58b-51c9576fc0be","uri":"","name":"careers.homedepot.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"afe421c9-985f-42fc-8474-48052b56f6f8","sortOrder":14},"sortOrder":14,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"ea4aeb97-3ade-4347-bfed-65fe221049b0","code":"home-depot-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"5f24c73a-c5e7-4a81-855f-1ac332b8d779","startsAt":"2026-09-08T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Retail","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/6f50/3c66/98093866/26a2d20e6151b1a4cbb891dcad8b1783_Screenshot_2026-09-18_at_11.38.23_AM.png","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-09-08T18:00:00.546Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/home-depot-vdp-pro","changelogs":"/engagements/home-depot-vdp-pro/changelog","submissions":null,"announcements":"/engagements/home-depot-vdp-pro/announcements","hallOfFame":"/engagements/home-depot-vdp-pro/hall_of_fames","crowdstream":"/engagements/home-depot-vdp-pro/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/home-depot-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=home-depot-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/home-depot-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/home-depot-vdp-pro/changelog","publishedAt":"2026-09-08T22:22:20.680Z","engagementChangelogUrl":"/engagements/home-depot-vdp-pro/changelog/693fa647-f03e-4cd2-aa47-aaa66c3e3a9f","createUserFeedbacksUrl":"/engagements/home-depot-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/home-depot-vdp-pro/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}