{"id":"2072dc5e-3e60-414e-9642-4228c9f7e687","engagementId":"bf83b8d4-fd9a-4c3b-bc6f-1be3c262e97b","data":{"brief":{"id":"f293c224-a14c-4bca-9156-f16d645fc77d","name":"Lucid Motors Vulnerability Disclosure Program","tagline":"At Lucid we aim to create sustainable mobility without compromise in cars that are intuitive, liberating, and designed for all the ways people get around.","description":"\u003cp\u003eLucid Motors cares deeply about maintaining the trust and confidence that our customers place in us. As such, the security of our systems, applications, and data is paramount. If you are a security researcher and have discovered a security vulnerability in one of our services, we appreciate your help in disclosing it to us in a responsible manner. No technology is perfect and Lucid Motors believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate on our program to help us identify vulnerabilities. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Lucid Motors not explicitly listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Lucid , you can report it to this program. However, be aware that it is ineligible for rewards.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003ePlease add an HTTP header to your request to access the target. For example:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eX-Bug-Bounty: Bugcrowd-\u0026lt;Username\u0026gt;\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eIdentifier\u003c/th\u003e\n\u003cth\u003eHeader\u003c/th\u003e\n\u003cth\u003eExample\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eUsername\u003c/td\u003e\n\u003ctd\u003eX-Bug-Bounty: Bugcrowd-\u0026lt;Username\u0026gt;\u003c/td\u003e\n\u003ctd\u003eX-Bug-Bounty: Bugcrowd-proresearcher\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003cp\u003eTarget is accessible via public internet. \u003c/p\u003e\n\n\u003ch2\u003eVulnerability Disclosure Guidelines:\u003c/h2\u003e\n\n\u003cp\u003eWe will investigate legitimate reports and make every effort to quickly correct any vulnerability. To encourage responsible reporting, we will not take legal action nor ask law enforcement to investigate you, provided you comply with the following :\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eEngage in this program in good faith and in compliance with all applicable laws\u003c/li\u003e\n\u003cli\u003eProvide details of the vulnerability, including the methodology and any other information needed to reproduce and validate the vulnerability. Where possible, provide a Proof of Concept \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eCross-site scripting,\u003c/li\u003e\n\u003cli\u003eCross-site request forgery\u003c/li\u003e\n\u003cli\u003eMixed-content scripts\u003c/li\u003e\n\u003cli\u003eAuthentication or authorization flaws\u003c/li\u003e\n\u003cli\u003eServer-side code execution bug\u003c/li\u003e\n\u003cli\u003eBuffer Overflow\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eLucid Motors manufacturing environment\u003c/li\u003e\n\u003cli\u003eLucid Motors MFA issues\u003c/li\u003e\n\u003cli\u003eWAF bypass\u003c/li\u003e\n\u003cli\u003eOpen redirects / Lack of security speedbump when leaving the site\u003c/li\u003e\n\u003cli\u003eInternal IP address disclosure\u003c/li\u003e\n\u003cli\u003eAccessible Non-sensitive files and directories (e.g. README.TXT, CHANGES.TXT, robots.txt, .gitignore, etc.)\u003c/li\u003e\n\u003cli\u003eSocial engineering / phishing attacks\u003c/li\u003e\n\u003cli\u003eSelf XSS\u003c/li\u003e\n\u003cli\u003eText injection\u003c/li\u003e\n\u003cli\u003eEmail spoofing (including SPF, DKIM, DMARC, From: spoofing, and visually similar, and related issues)\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g., stack traces, application or server errors, path disclosure)\u003c/li\u003e\n\u003cli\u003eFingerprinting/banner disclosure on common/public services\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking\u003c/li\u003e\n\u003cli\u003eCSRF issues that don't impact the integrity of an account (e.g., log in or out, contact forms and other publicly accessible forms)\u003c/li\u003e\n\u003cli\u003eLack of Secure and HTTPOnly cookie flags (critical systems may still be in scope)\u003c/li\u003e\n\u003cli\u003eLack of rate limiting\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force, account lockout not enforced, or insufficient password strength requirements\u003c/li\u003e\n\u003cli\u003eHTTPS mixed content scripts\u003c/li\u003e\n\u003cli\u003eUsername / email enumeration by brute forcing / error messages (e.g., login /signup / forgotten password)\u003c/li\u003e\n\u003cli\u003eExceptional cases may still be in scope (e.g., ability to enumerate email addresses via incrementing a numeric parameter)\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers\u003c/li\u003e\n\u003cli\u003eTLS/SSL Issues, including BEAST BREACH, insecure renegotiation, bad cipher suite, expired certificates, etc.\u003c/li\u003e\n\u003cli\u003eDenial of Service attacks\u003c/li\u003e\n\u003cli\u003eOut-of-date software\u003c/li\u003e\n\u003cli\u003eUse of a known-vulnerable component (exceptional cases, such as where you are able to provide proof of exploitation, may still be in scope)\u003c/li\u003e\n\u003cli\u003ePhysical attacks against Lucid Motor’s Facilities / Property\u003c/li\u003e\n\u003cli\u003eRelay or RollJam attacks pertaining to the keyfob, NFC card, and/or phone-as-key\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"13df40a1-f3c6-457d-9320-7b7c2d381474","name":"In Scope Targets","targets":[{"id":"33e6dd1b-cd21-47b8-94d4-9f23aa9ce625","uri":"https://www.lucidmotors.com","name":"www.lucidmotors.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a54bbda7-603f-416d-9a0d-82b9c23463c4","sortOrder":0},"sortOrder":0,"tags":[{"id":"21bf0b21-e645-4730-b030-be773c64efc7","name":"Gatsby","targetId":"33e6dd1b-cd21-47b8-94d4-9f23aa9ce625"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"33e6dd1b-cd21-47b8-94d4-9f23aa9ce625"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"33e6dd1b-cd21-47b8-94d4-9f23aa9ce625"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null},{"id":"dba9869b-c493-4f9b-b21e-190682ff7769","name":"Out Of Scope ","targets":[{"id":"54d8028a-2bf5-444e-9eb3-0536f28501aa","uri":"","name":"All Internal Applications","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a9c94e5d-caa6-4597-9fd0-f885896e3477","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"54d8028a-2bf5-444e-9eb3-0536f28501aa"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"bf83b8d4-fd9a-4c3b-bc6f-1be3c262e97b","code":"lucidmotors-vdp","state":"in_progress","endsAt":null,"bountyId":"5270ad38-a2f9-4d4f-a544-cf613885bc7f","startsAt":"2022-04-28T19:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/7f11/eb70/3e3d2a8c/8d4ffe2cf0ba34f00b0dce937f041e44_Screen_Shot_2022-04-22_at_10.15.29_AM.png","logoBackgroundColor":"#000000","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-01-20T01:28:44.740Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/lucidmotors-vdp","changelogs":"/engagements/lucidmotors-vdp/changelog","submissions":null,"announcements":"/engagements/lucidmotors-vdp/announcements","hallOfFame":"/engagements/lucidmotors-vdp/hall_of_fames","crowdstream":"/engagements/lucidmotors-vdp/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/lucidmotors-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=lucidmotors-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/lucidmotors-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/lucidmotors-vdp/changelog","publishedAt":"2026-01-20T01:28:44.767Z","engagementChangelogUrl":"/engagements/lucidmotors-vdp/changelog/2072dc5e-3e60-414e-9642-4228c9f7e687","createUserFeedbacksUrl":"/engagements/lucidmotors-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/lucidmotors-vdp/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}