{"id":"884450ef-4277-41a9-8394-5f8c49cae2d8","engagementId":"3fa62a15-7e82-4c7b-9af2-82ab4b059aa9","data":{"brief":{"id":"13569ad9-f426-42f0-9cde-30040bbd9cca","name":"LaunchDarkly Managed Bug Bounty Engagement","tagline":"Move at AI speed. Stay in control. ","description":"\u003cp\u003eLaunchDarkly is the runtime control platform for releases, AI behavior, and customer experiences in real time with no redeploys required. As the pioneer of feature management, LaunchDarkly introduced a new way for engineering teams to separate code deployment from feature release, allowing organizations to innovate faster while reducing risk in production.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003eOur rewards are based on severity per CVSS (the Common Vulnerability Scoring Standard). However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of LaunchDarkly not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to LaunchDarkly, you can report it here. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eEngagement Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe do not accept reports that contain low-effort or AI-generated content. Submissions must demonstrate original analysis, clear understanding of the issue, and actionable detail. Reports lacking meaningful human input will be rejected\u003c/li\u003e\n\u003cli\u003eAll accounts must be created using your @bugcrowdninja email address, or otherwise include the substring \u003ccode\u003ebugcrowd\u003c/code\u003e (eg, \u003ccode\u003eyour.name+bugcrowd1234@example.com\u003c/code\u003e is permissible)\u003c/li\u003e\n\u003cli\u003eSubmissions related to SSRF vulnerabilities, including webhook-based SSRF attacks, must include proof that the target endpoint was reached along with the associated metadata\u003c/li\u003e\n\u003cli\u003ePotential post-exploitation scenarios: If you believe you've identified a vulnerability that may lead to post-exploitation activity including modification or destruction of data please stop testing and submit your finding. We will work with you to evaluate the vulnerability and award you accordingly for the final impact and severity\u003c/li\u003e\n\u003cli\u003eYou are testing on production. Behavior that compromises the stability and integrity of the target(s) is out of scope.\n\n\u003cul\u003e\n\u003cli\u003e For example, do not target other users' data (use one of your other sets of credentials), delete/remove/edit parts of the site, engage any sort of DoS attack, and/or compromise any target's ability to function for other users. If you believe that you have found a vulnerability of this nature, please stop further testing and report it\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eReport Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities discovered on multiple paths, endpoints, parameters will be treated as duplicates. This includes findings across different environments (e.g., development, staging, production) unless the impact or exploitation method is materially different. Please submit only one report\u003c/li\u003e\n\u003cli\u003eReports must contain the role used for testing, a clear explanation of the issue and the security impact along with detailed steps to reproduce it. If the issue cannot be reliably reproduced based on your report, it may be considered ineligible for a reward\u003c/li\u003e\n\u003cli\u003eDo not submit more than one vulnerability per report. In cases where demonstrating impact requires chaining multiple vulnerabilities together, those can be included in the same report as long as the linkage is clearly explained\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess\u003c/h2\u003e\n\n\u003cp\u003eAll targets within scope are publicly accessible. \u003c/p\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cp\u003eTo support your testing, we’ve highlighted several key areas of interest. While we ask that you report any efforts related to these areas, please note that testing is not limited to them. Submissions outside of these focus areas are equally welcomed and appreciated.\u003c/p\u003e\n\n\u003cp\u003e\u003ccode\u003eapp.launchdarkly.com\u003c/code\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eImproper authentication/access control\u003c/li\u003e\n\u003cli\u003eUser privilege escalation to perform actions not defined in role\u003c/li\u003e\n\u003cli\u003eXSS/SSRF in user input fields\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eAdditionally, we'd like to call special attention to the following application components that we recently released for general availability:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCustom Contexts: We've recently updated the platform's user model to support customer-defined contexts (e.g. users, devices, business units, organizations) for flag targeting. While this change in the underlying model should generally be a 1 for 1 replacement (i.e., users -\u0026gt; custom contexts), we'd be interested to see if the new infrastructure, UI components, etc. created to support custom contexts are susceptible to any web application vulnerabilities or business logic errors. For more details, see the following docs:\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://docs-stg.launchdarkly.com/contexts-eap/guides/flags/intro-contexts\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eIntroduction to contexts\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://docs.launchdarkly.com/guides/flags/upgrading-contexts\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBest practices for upgrading users to contexts\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eExperimentation: In 2022 we launched a refresh our experimentation offering which allows customers to use feature flags in conjunction with events tracking to evaluate how feature flags affect key performance metrics. We'd be interested in any potential vulnerabilities or logic errors that arise from creating and running experiments within the platform.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003ccode\u003eapp.launchdarkly.com/api/v2/\u003c/code\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eUnauthenticated/unauthorized access to APIs\u003c/li\u003e\n\u003cli\u003eAPIs returning unexpected data (e.g. data from different accounts/environments, data the user role should not have access to, etc.)\u003c/li\u003e\n\u003cli\u003eHandler logic errors that cause unexpected/undefined behavior\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003ccode\u003eLaunchDarkly SDKs\u003c/code\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOur SDKs are open source and are available on Github (e.g. React client SDK). We encourage researchers to dig into the open source code if interested.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cp\u003eWhen N-Day bugs are released to the public and can be exploited within our target(s), please let us know immediately. Each report will be reviewed on a case by case basis\u003c/p\u003e\n\n\u003ch2\u003eLeaked Credentials\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003e\u003cstrong\u003eLaunchDarkly credentials that have been leaked are only eligible if\u003c/strong\u003e\u003c/em\u003e:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCustomer credentials that were leaked through some action or inaction of LaunchDarkly (ie, a customer checking their own API token into Github would not be eligible)\u003c/li\u003e\n\u003cli\u003eThey are not meant to be made public (the browser SDK operates using a token that is intended to be embedded in publicly-exposed source code)\u003c/li\u003e\n\u003cli\u003eTokens belonging to LaunchDarkly-controlled accounts, that have the \"bountyEligible\": true value in the /api/v2/caller-identity response. This excludes testing accounts, and other accounts with no valuable data\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003ccode\u003estream.launchdarkly.com\u003c/code\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eGenerally, we're looking for ways that attackers could exploit our flag evaluation logic to improperly retrieve flag information meant for other users. Client-side SDKs are specifically meant to prevent attackers from accessing things such as flag evaluation rules due to the untrusted nature of client devices, so any improper handling/exposure of this data may be considered noteworthy.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003ccode\u003eevents.launchdarkly.com\u003c/code\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe'd be interested in ways that attackers may want to exploit our event recording mechanisms.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003ccode\u003edocs.launchdarkly.com\u003c/code\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe site is mostly static, but there are user input fields (e.g. search bar) that we'd want to ensure are not vulnerable to any XSS or other injection vulnerablities. The site also makes cross-origin requests to app.launchdarkly.com, so any potential CSRF vulnerabilities would be noteworthy.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eKnown Issue\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003ePlease note that the following issues are considered known risks and will not be eligible for bounties:\u003c/em\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eRate limiting on account verification and forgot password pages\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eSupport team interfaces, such as chat bots, forms, or other methods which generate emails, tickets, or notifications for the LaunchDarkly support teams. There are real people on the other end, and junk requests are a drain on their resources.\u003c/li\u003e\n\u003cli\u003eThird party integrations and endpoints \n\n\u003cul\u003e\n\u003cli\u003eLaunchDarkly provides a handful of third party integrations for use by customers. While these aren't considered in scope today, we are working on refining our testing methodologies for these integrations and plan on making these available for testing in our program in the future.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAvailability/volumetric testing e.g.:\n\n\u003cul\u003e\n\u003cli\u003eDoS/DDoS/Network DoS\u003c/li\u003e\n\u003cli\u003eRate limiting bypass attempts\u003c/li\u003e\n\u003cli\u003eEmail bombing or flooding\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eALL forms of social Engineering\u003c/li\u003e\n\u003cli\u003eClickjacking on pages with no sensitive actions\u003c/li\u003e\n\u003cli\u003eCross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions\u003c/li\u003e\n\u003cli\u003eAttacks requiring MITM or physical access to a user's device.\u003c/li\u003e\n\u003cli\u003ePreviously known vulnerable libraries without a working Proof of Concept.\u003c/li\u003e\n\u003cli\u003eComma Separated Values (CSV) injection without demonstrating a vulnerability specific to the LaunchDarkly platform. Vulnerabilities related to Excel interpreting and executing injected text are not in scope.\u003c/li\u003e\n\u003cli\u003eMissing best practices in SSL/TLS configuration.\u003c/li\u003e\n\u003cli\u003eAny activity that could lead to the disruption of our service (DoS).\u003c/li\u003e\n\u003cli\u003eContent spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS\u003c/li\u003e\n\u003cli\u003eRate limiting or bruteforce issues on non-authentication endpoints\u003c/li\u003e\n\u003cli\u003eMissing best practices in Content Security Policy.\u003c/li\u003e\n\u003cli\u003eMissing HttpOnly or Secure flags on cookies, except the ldso cookie.\u003c/li\u003e\n\u003cli\u003eMissing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affecting users of uncommonly-used browser extensions (eg, an extension designed to find redirect URLs embedded in the URL are designed to create open redirects on all URLs)\u003c/li\u003e\n\u003cli\u003eSoftware version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors).\u003c/li\u003e\n\u003cli\u003ePublic Zero-day vulnerabilities that have had an official patch for less than 1 month will be awarded on a case by case basis.\u003c/li\u003e\n\u003cli\u003eTabnabbing\u003c/li\u003e\n\u003cli\u003eOpen redirect - unless an additional security impact can be demonstrated\u003c/li\u003e\n\u003cli\u003eIssues that require unlikely user interaction\u003c/li\u003e\n\u003cli\u003eFindings related to non-SDK repositories (i.e., repos not ending in -sdk)\u003c/li\u003e\n\u003cli\u003eVulnerability/dependency scan results of our source code. Please try and dig into our source code more deeply than just reporting a scan result that we may already be aware of.\u003c/li\u003e\n\u003cli\u003eClient-side SDK keys (used by the JS SDK and mobile SDKs) are not required to be kept secret. Please don’t report that these are visible in a properly-deployed application of the service.\u003c/li\u003e\n\u003cli\u003eClient-side keys or tokens used on our website that are also not required to be kept secret. Examples include: Algolia search API key, TrackJS analytics token, etc.\u003c/li\u003e\n\u003cli\u003eJira ServiceDesk allowing public registration\u003c/li\u003e\n\u003cli\u003eVerification email inbox spam\u003c/li\u003e\n\u003cli\u003eHTML injection on text fields within the app or emails generated by the application\u003c/li\u003e\n\u003cli\u003ePassword reset link not expiring if email address changed\u003c/li\u003e\n\u003cli\u003eVulnerability scans / dependency scans on open source repositories\u003c/li\u003e\n\u003cli\u003eOpen source Github findings not related to our client and server SDKs (i.e., repos not suffixed by -sdk)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our \u003ca href=\"https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eTerms \u0026amp; Conditions\u003c/a\u003e  that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via our \u003ca href=\"https://bugcrowd-support.freshdesk.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eFreshDesk Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"422b4430-2c12-4565-a9b4-1e548da0487a","name":"In Scope ","targets":[{"id":"d9d4dac7-e228-42ae-8c84-83132c7ab685","uri":"","name":"app.launchdarkly.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"026184a0-f63b-4266-93e8-5993eb1b1c0d","sortOrder":0},"sortOrder":0,"tags":[{"id":"30a3c3f4-5f27-4be7-9e4f-5fe8e80828f8","name":"Elasticsearch","targetId":"d9d4dac7-e228-42ae-8c84-83132c7ab685"},{"id":"95cf953e-85ee-42c2-9123-09d81bfe7ba9","name":"PostgreSQL","targetId":"d9d4dac7-e228-42ae-8c84-83132c7ab685"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"d9d4dac7-e228-42ae-8c84-83132c7ab685"},{"id":"a41318b7-d0b8-4b39-8250-dbbad194e770","name":"MongoDB","targetId":"d9d4dac7-e228-42ae-8c84-83132c7ab685"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"d9d4dac7-e228-42ae-8c84-83132c7ab685"}],"recentChangeFlags":null},{"id":"2967410d-9742-4a3a-9b68-08fd799f66e0","uri":"","name":"events.launchdarkly.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"abb39ee5-660c-4728-96ab-89b024962908","sortOrder":1},"sortOrder":1,"tags":[{"id":"30a3c3f4-5f27-4be7-9e4f-5fe8e80828f8","name":"Elasticsearch","targetId":"2967410d-9742-4a3a-9b68-08fd799f66e0"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"2967410d-9742-4a3a-9b68-08fd799f66e0"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"2967410d-9742-4a3a-9b68-08fd799f66e0"},{"id":"95cf953e-85ee-42c2-9123-09d81bfe7ba9","name":"PostgreSQL","targetId":"2967410d-9742-4a3a-9b68-08fd799f66e0"},{"id":"a41318b7-d0b8-4b39-8250-dbbad194e770","name":"MongoDB","targetId":"2967410d-9742-4a3a-9b68-08fd799f66e0"}],"recentChangeFlags":null},{"id":"44171231-3c39-436a-afa2-57c627984481","uri":"","name":"stream.launchdarkly.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7cfa14fa-000c-43c5-bb47-22610a1e694c","sortOrder":2},"sortOrder":2,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"44171231-3c39-436a-afa2-57c627984481"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"44171231-3c39-436a-afa2-57c627984481"}],"recentChangeFlags":null},{"id":"20b9e679-0664-42e1-8fe7-a1256de53547","uri":"","name":"LaunchDarkly Open Source SDKs","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"6ac7eb49-ff27-4063-a614-b2f46a2ad142","sortOrder":3},"sortOrder":3,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"20b9e679-0664-42e1-8fe7-a1256de53547"},{"id":"1f10e73e-4eef-42c1-ba6b-6df69f8dc8fa","name":"Rust","targetId":"20b9e679-0664-42e1-8fe7-a1256de53547"},{"id":"5eb88719-7cae-4dff-b2b1-f199b23d82de","name":"Haskell","targetId":"20b9e679-0664-42e1-8fe7-a1256de53547"},{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"20b9e679-0664-42e1-8fe7-a1256de53547"},{"id":"68da3fae-5355-463e-8442-9a5016b1bda0","name":"ASP.NET","targetId":"20b9e679-0664-42e1-8fe7-a1256de53547"},{"id":"86402f5d-20d0-4c88-92b9-0994786e4241","name":"C++","targetId":"20b9e679-0664-42e1-8fe7-a1256de53547"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"20b9e679-0664-42e1-8fe7-a1256de53547"},{"id":"9ffd297c-4781-4777-94cf-ef4e2ddda266","name":"C#","targetId":"20b9e679-0664-42e1-8fe7-a1256de53547"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"20b9e679-0664-42e1-8fe7-a1256de53547"},{"id":"ce8ff3cd-4d54-4404-8321-6351781551a3","name":"Vue.js","targetId":"20b9e679-0664-42e1-8fe7-a1256de53547"},{"id":"dd477d24-b394-460d-aaf7-9bd213555968","name":"Ruby","targetId":"20b9e679-0664-42e1-8fe7-a1256de53547"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"20b9e679-0664-42e1-8fe7-a1256de53547"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"20b9e679-0664-42e1-8fe7-a1256de53547"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"20b9e679-0664-42e1-8fe7-a1256de53547"}],"recentChangeFlags":null},{"id":"e6660cad-f0d4-4844-ba34-de5208915e3d","uri":"","name":"docs.launchdarkly.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"96e82594-83ac-4e66-a8ef-07b6abfdff0f","sortOrder":4},"sortOrder":4,"tags":null,"recentChangeFlags":null},{"id":"6457419f-1d5a-4f55-8e77-8c3f73b33ad4","uri":"https://launchdarkly.com/docs","name":"https://launchdarkly.com/docs","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"316821d9-547b-4ac6-8fd5-403ed83dd0d3","sortOrder":5},"sortOrder":5,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"7347e6f2-0311-4161-a667-d47916a7bd38","p1MaxCents":750000,"p1MinCents":650000,"p2MaxCents":250000,"p2MinCents":250000,"p3MaxCents":125000,"p3MinCents":125000,"p4MaxCents":15000,"p4MinCents":15000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eTarget Overview\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eLaunchDarkly frontend\u003c/strong\u003e \u003ccode\u003eapp.launchdarkly.com\u003c/code\u003e\u003c/p\u003e\n\n\u003cp\u003eThe main LaunchDarkly application and point of entry. LaunchDarkly customers use this interface to log into the application and manage feature flags, context types, segments, and so on. Admin level users may also manage their LaunchDarkly organization (i.e. users, roles, environments) from this interface.\u003c/p\u003e\n\n\u003cp\u003eHow to test: Please create an account with your @bugcrowdninja email address in order to receive an account with full access to all features on the LaunchDarkly platform. Documentation for how to use LaunchDarkly may be found on our \u003ca href=\"https://docs.launchdarkly.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003edocs website\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eLaunchDarkly APIs\u003c/strong\u003e \u003ccode\u003eapp.launchdarkly.com/api/v2/\u003c/code\u003e\u003c/p\u003e\n\n\u003cp\u003eProvides the backend APIs for the LaunchDarkly application\u003c/p\u003e\n\n\u003cp\u003eThe /api/v2/ and /internal/ subroutes are customer-facing APIs and require either a valid ldso session cookie or an access token in the Authorization header for authentication. You may create an access token from the Account Settings page in the UI for use in API testing. If you prefer to use the session cookie, the ldso token may be retrieved from your own browser after logging into the UI.\u003cbr\u003e\nConversely, the /private/ APIs are not meant to allow authentication to any non-LaunchDarkly users and use a separate authentication mechanism. Any cases where these endpoints are improperly accessible are worthy of note.\u003c/p\u003e\n\n\u003cp\u003eOur external-facing API documentation may be found here: \u003ca href=\"https://apidocs.launchdarkly.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAPI docs\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eLaunchDarkly SDKs\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eWhat they do: SDKs are integrated into customer applications to evaluate LaunchDarkly feature flags the application. LaunchDarkly provides a wide range of SDKs for various languages and platforms, documented here: \u003ca href=\"https://docs.launchdarkly.com/sdk\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSDK docs\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003eWe encourage researchers to integrate SDKs with custom applications and test the communication between the SDKs and LaunchDarkly\u0026#39;s servers (see more details in the streamer/event recorder sections below). You\u0026#39;ll need to generate an SDK key/client ID from the UI in order to initialize the SDK\u0026#39;s connection with LaunchDarkly. We\u0026#39;d be interested in any general API vulnerability findings as well as any handler logic vulnerabilities that you may find.\u003c/p\u003e\n\n\u003cp\u003eAdditionally, our SDKs are open source and are available on Github (e.g. React client SDK). We encourage researchers to dig into the open source code if interested. \u003cstrong\u003eHowever, we will not be accepting the following types of findings\u003c/strong\u003e:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eFindings related to non-SDK repositories (i.e., repos not ending in -sdk)\u003c/li\u003e\n\u003cli\u003eVulnerability/dependency scan results of our source code. Please try and dig into our source code more deeply than just reporting a scan result that we may already be aware of.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eStreamer\u003c/strong\u003e \u003ccode\u003estream.launchdarkly.com\u003c/code\u003e\u003c/p\u003e\n\n\u003cp\u003eStreamer provides flag information for server and client SDKs for flag evaluation. SDKs maintain connectivity with distributed streamer nodes and receive flag updates as changes are made in the platform in real time, allowing end user clients to react instantaneously and update the application accordingly.\u003c/p\u003e\n\n\u003cp\u003estreamer.launchdarkly.com exposes a set of routes for retrieving flag data depending on whether the SDK is client or server-side (see the distinction here: \u003ca href=\"https://docs.launchdarkly.com/sdk/concepts/client-side-server-side\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eclient vs server SDKs\u003c/a\u003e).\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eEvent Recorder\u003c/strong\u003e \u003ccode\u003eevents.launchdarkly.com\u003c/code\u003e\u003c/p\u003e\n\n\u003cp\u003eOnce flags are evaluated by the client/server SDKs, these SDKs will record and send events to \u003ccode\u003eevents.launchdarkly.com\u003c/code\u003e for metrics collection. This allows customers to collect data about things such as which flags are being evaluated, how many times flags are evaluated, which contexts are being targeted, etc.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eDocs Site\u003c/strong\u003e \u003ccode\u003edocs.launchdarkly.com\u003c/code\u003e\u003c/p\u003e\n\n\u003cp\u003eStatic site hosting LaunchDarkly documentation (i.e. installation/user/admin guides, API references, etc.)\u003c/p\u003e","rewardRangeData":{"1":{"min":6500,"max":7500},"2":{"min":2500,"max":2500},"3":{"min":1250,"max":1250},"4":{"min":150,"max":150},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"42d7b9a4-a9fe-4625-9085-5059f60519b8","name":"Out of Scope ","targets":[{"id":"2b3093b5-09be-4cc8-a870-5f7546844609","uri":"","name":"blog.launchdarkly.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"78d8a60a-20af-4a1a-87d8-1fde0b751836","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"de573078-57d7-4146-b808-71f00ac15992","uri":"","name":"launchdarkly.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5e19271c-fe95-4475-b69c-3e186eb85cf6","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"ad9ba92d-7b11-4291-b728-d08779953c37","uri":"","name":"sandbox.launchdarkly.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8beec610-9832-4648-81a7-4a6272e7c4de","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null},{"id":"6d10cae1-e02d-4d2a-8fa9-c9b8908e7a06","uri":"","name":"slack.launchdarkly.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a6c1b546-ad39-493a-8226-f7454bc39dcb","sortOrder":3},"sortOrder":3,"tags":null,"recentChangeFlags":null},{"id":"df3f9e2b-0d32-4e58-a0e1-4e6e810392dd","uri":"","name":"status.launchdarkly.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4b3387a2-1432-468d-9c1c-9c76b54e8ee8","sortOrder":4},"sortOrder":4,"tags":null,"recentChangeFlags":null},{"id":"d6ba1a88-6c16-4097-ab2a-e426c959ae9d","uri":"https://launchdarkly.atlassian.net","name":"launchdarkly.atlassian.net","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"52ca2b81-147a-4290-8cba-7f69598730c4","sortOrder":5},"sortOrder":5,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"3fa62a15-7e82-4c7b-9af2-82ab4b059aa9","code":"launchdarkly-mbb-og","state":"in_progress","endsAt":null,"bountyId":"0f41166e-1fe7-4e32-9b9e-2d3796455378","startsAt":"2026-05-19T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/e720/19af/d74562be/68b4e5e9d7381f76a0e8279426261aec_launchdarkly_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-05-19T18:00:00.462Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/launchdarkly-mbb-og","changelogs":"/engagements/launchdarkly-mbb-og/changelog","submissions":null,"announcements":"/engagements/launchdarkly-mbb-og/announcements","hallOfFame":"/engagements/launchdarkly-mbb-og/hall_of_fames","crowdstream":null},"announcementsCount":3,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/launchdarkly-mbb-og/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=launchdarkly-mbb-og\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/launchdarkly-mbb-og/engagement_subscribers","engagementChangelogsUrl":"/engagements/launchdarkly-mbb-og/changelog","publishedAt":"2026-08-13T16:49:44.673Z","engagementChangelogUrl":"/engagements/launchdarkly-mbb-og/changelog/884450ef-4277-41a9-8394-5f8c49cae2d8","createUserFeedbacksUrl":"/engagements/launchdarkly-mbb-og/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}