{"id":"6b90f7f3-355b-406d-848e-3dfb0622f02a","engagementId":"22e006a9-8881-4500-97b6-ccf09ead9904","data":{"brief":{"id":"6900977d-a708-4e6a-8b14-cc2431e7ed85","name":"MATLAB Online - Ongoing Bug Bounty Engagement","tagline":"MATLAB Online extends the capabilities of MATLAB and Simulink to the cloud","description":"\u003cp\u003eMATLAB Online extends the capabilities of MATLAB and Simulink to the cloud. You can connect to cloud storage solutions and collaborate on projects through a web browser without installing software. With support for hardware integration and scalable cloud computing, MATLAB Online enhances your workflow for flexible, on-the-go productivity. Good luck and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as In-Scope. Any domain/property of MathWorks not listed explicitly in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in-scope, but that demonstrably belongs to MathWorks, it may be reported through the Vulnerability Disclosure Policy (VDP). More details are available here - \u003ca href=\"https://www.mathworks.com/company/trust-center/vulnerability-disclosure-policy.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eVulnerability Disclosure Policy for Security Researchers - MATLAB \u0026amp; Simulink\u003c/a\u003e. Note that VDP submissions are ineligible for rewards or points-based compensation. Please do not submit duplicate submissions across programs. For in-scope target disputed reports, use the \u003ca href=\"https://docs.bugcrowd.com/researchers/reporting-managing-submissions/researchers-unread-comments/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd platform\u003c/a\u003e to request re-assessment.\u003c/em\u003e \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eEngagement Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe do not accept reports that contain low-effort or AI-generated content. Submissions must demonstrate original analysis, clear understanding of the issue, and actionable detail. Reports lacking meaningful human input will be rejected\u003c/li\u003e\n\u003cli\u003ePotential post-exploitation scenarios: If you believe you've identified a vulnerability that may lead to post-exploitation activity including modification or destruction of data please stop testing and submit your finding. We will work with you to evaluate the vulnerability and award you accordingly for the final impact and severity\u003c/li\u003e\n\u003cli\u003eTesting is only allowed on content created by your @bugcrowdninja.com Account\u003c/li\u003e\n\u003cli\u003eAny Stored XSS vulnerabilities found in the MATLAB Online will be considered as P3 unless demonstrated to have wider and more severe impact\u003c/li\u003e\n\u003cli\u003eStored XSS vulnerabilities through file names will be considered P3\u003c/li\u003e\n\u003cli\u003eUnique, complex, and impactful findings may be elevated to P2 based on demonstrated steps and impact\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eReport Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities discovered on multiple paths, endpoints, parameters will be treated as duplicates. This includes findings across different environments (e.g., development, staging, production) unless the impact or exploitation method is materially different. Please submit only one report\u003c/li\u003e\n\u003cli\u003eReports must contain the role used for testing (if any), a clear explanation of the issue and the security impact along with detailed steps to reproduce it. If the issue cannot be reliably reproduced based on your report, it may be considered ineligible for a reward\u003c/li\u003e\n\u003cli\u003eDo not submit more than one vulnerability per report. In cases where demonstrating impact requires chaining multiple vulnerabilities together, those can be included in the same report as long as the linkage is clearly explained\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess\u003c/h2\u003e\n\n\u003cp\u003eTo ensure uninterrupted access and avoid rate-limiting or blocking during your testing, please include the following custom HTTP header in all of your requests:\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eRequired\u003c/strong\u003e\u003cbr\u003e\n\u003ccode\u003eX-Request-Purpose: BugcrowdResearch\u003c/code\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eOptional\u003c/strong\u003e\u003cbr\u003e\n\u003ccode\u003eX-Bugcrowd-Ninja: [username]\u003c/code\u003e\u003c/p\u003e\n\n\u003cp\u003eThis helps us identify legitimate testing traffic and prevent accidental interference with real users or automated systems. Failure to include this header may result in your requests being blocked.\u003c/p\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003e** Testing is only allowed on content created by your @bugcrowdninja.com Account**\u003c/p\u003e\n\n\u003cp\u003eMathworks offers Researchers Trial Licenses to access the In-scope Targets. In order to activate a trial license, create a \u003ca href=\"https://matlab.mathworks.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eMATLAB Online Account\u003c/a\u003e with your \u003cstrong\u003ebugcrowdninja\u003c/strong\u003e email address and then visit the \u003ca href=\"https://www.mathworks.com/licensecenter/classroom/MO_3070650/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eMathWorks Researcher Intake\u003c/a\u003e and sign in using your account which will give you license to access MATLAB Online. Once the license association is complete you should use the production stack (https://matlab.mathworks.com/) for all the testing. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cp\u003eTo support your testing, we’ve highlighted several key areas of interest. While we ask that you report any efforts related to these areas, please note that testing is not limited to them. Submissions outside of these focus areas are equally welcomed and appreciated.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCross Site Scripting (XSS)\u003c/li\u003e\n\u003cli\u003eCross-Site Request Forgery (CSRF)\u003c/li\u003e\n\u003cli\u003eSQL Injection (SQLi)\u003c/li\u003e\n\u003cli\u003eAuthentication related issues\u003c/li\u003e\n\u003cli\u003eAuthorization related issues\u003c/li\u003e\n\u003cli\u003eData Exposure\u003c/li\u003e\n\u003cli\u003eRemote Code Execution\u003c/li\u003e\n\u003cli\u003eAny vulnerabilities that allow a user to escape from the Docker container to the host operating system\u003c/li\u003e\n\u003cli\u003eParticularly clever vulnerabilities or unique issues that do not fall into explicit categories\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eStandards\u003c/h2\u003e\n\n\u003cp\u003ePersistent testing on any publicly facing functionality is not permitted. Any created content must be deleted within FIVE minutes. A non-exhaustive list of things to be careful about is:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eContacting sales.\u003c/li\u003e\n\u003cli\u003eDo not submit a bug report or contact technical or customer support. The service request feature of the \u003ca href=\"https://www.mathworks.com/mwaccount/?s_tid=gn_myac\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eMathWorks Account profile page\u003c/a\u003e \u003cem\u003ewill\u003c/em\u003e open service requests. Using this feature is prohibited by this brief.\u003c/li\u003e\n\u003cli\u003eAnd again, anything that's publicly visible and persistent\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eAny testing that results in temporary content being displayed must look normal to our regular site visitors and be \u003cstrong\u003enon-malicious\u003c/strong\u003e. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003ch5\u003eThe following finding types are specifically excluded from the bounty:\u003c/h5\u003e\n\n\u003cul\u003e\n\u003cli\u003eDenial of Service attacks of any type.\u003c/li\u003e\n\u003cli\u003eOpen redirects (through headers and parameters) / Lack of security speedbump when leaving the site\u003c/li\u003e\n\u003cli\u003eInternal IP address disclosure\u003c/li\u003e\n\u003cli\u003eAccessible non-sensitive files and directories (e.g., README.TXT, CHANGES.TXT, robots.txt, gitignore, etc.)\u003c/li\u003e\n\u003cli\u003eSocial engineering/phishing attacks\u003c/li\u003e\n\u003cli\u003eSelf XSS\u003c/li\u003e\n\u003cli\u003eText injection\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g., stack traces, application/server errors, path disclosure)\u003c/li\u003e\n\u003cli\u003eFingerprinting/banner disclosure on common/public services.\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking.\u003c/li\u003e\n\u003cli\u003eCSRF issues that don't impact the integrity of an account (e.g. login or out, contact forms and other publicly accessible forms)\u003c/li\u003e\n\u003cli\u003eEmail spoofing, lack of DMARC, SPF records, or DKIM configuration\u003c/li\u003e\n\u003cli\u003eLack of Secure and HTTPOnly cookie flags (critical systems may still be in scope).\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force, account lockout not enforced, or insufficient password strength requirements\u003c/li\u003e\n\u003cli\u003eHTTPS mixed content scripts.\u003c/li\u003e\n\u003cli\u003eUsername / email enumeration by brute forcing / error messages (e.g. login / signup / forgotten password).\n\n\u003cul\u003e\n\u003cli\u003eExceptional cases may still be in scope (e.g. ability to enumerate email addresses via incrementing a numeric parameter).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eTLS/SSL configuration issues are not in scope unless they are egregious. Lack of pinning or allowing theoretically insecure cipher-suites is not in scope.\u003c/li\u003e\n\u003cli\u003eBugs that don't work in the latest version of Chrome, Firefox, Safari, IE11, and Edge\u003c/li\u003e\n\u003cli\u003eOut-of-date software or use of a known-vulnerable component (exceptional cases, such as where you are able to provide proof of exploitation, may still be in scope)\u003c/li\u003e\n\u003cli\u003eLack of rate limiting on login, registration, or email generating forms.\u003c/li\u003e\n\u003cli\u003eAttempt to overwhelm the LLM by sending an excessive number of requests in a short period (exceeding 25 within a minute), you may not receive the anticipated response and will be blocked. \u003c/li\u003e\n\u003cli\u003eThe presence of virus scanning on uploaded files\u003c/li\u003e\n\u003cli\u003eContent admin pages present on the Internet.\u003c/li\u003e\n\u003cli\u003eSecurity issues in 3rd party services, applications.\u003c/li\u003e\n\u003cli\u003eWeak Captcha / Captcha Bypass\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers, specifically (https://www.owasp.org/index.php/List_of_useful_HTTP_headers), e.g.\n\n\u003cul\u003e\n\u003cli\u003eStrict-Transport-Security\u003c/li\u003e\n\u003cli\u003eX-Frame-Options\u003c/li\u003e\n\u003cli\u003eX-XSS-Protection\u003c/li\u003e\n\u003cli\u003eX-Content-Type-Options\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy, X-Content-Security-Policy, X-WebKit-CSP\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy-Report-Only\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eThe following SSL Issues:\n\n\u003cul\u003e\n\u003cli\u003eSSL Attacks such as BEAST, BREACH, Renegotiation attack\u003c/li\u003e\n\u003cli\u003eSSL Forward secrecy not enabled\u003c/li\u003e\n\u003cli\u003eSSL weak / insecure cipher suites\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eEXIF meta-data not stripped on images\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut-of-scope for Stored XSS\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eXSS vulnerabilities that follow the same steps across different file types or extensions will be considered duplicates and are out of scope for additional rewards. For example, using same payload in different file types and opening in different apps within MATLAB Online will be considered as duplicates.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"b435e66e-b59f-47dc-8429-925b1cb9cc20","name":"In Scope ","targets":[{"id":"bb6de758-7eb4-43df-8086-d1c2550372f6","uri":"https://matlab.mathworks.com/","name":"https://matlab.mathworks.com/ [MATLAB ONLINE]","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5ff852d8-6b3e-4f41-b458-de204a1b7d0d","sortOrder":0},"sortOrder":0,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"bb6de758-7eb4-43df-8086-d1c2550372f6"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"bb6de758-7eb4-43df-8086-d1c2550372f6"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"bb6de758-7eb4-43df-8086-d1c2550372f6"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"bb6de758-7eb4-43df-8086-d1c2550372f6"},{"id":"16818e15-ac0f-4e76-999b-8b6a87db2837","name":"Docker","targetId":"bb6de758-7eb4-43df-8086-d1c2550372f6"},{"id":"e82bba17-848b-4f2b-a2a5-58d2a83530d4","name":"Kubernetes","targetId":"bb6de758-7eb4-43df-8086-d1c2550372f6"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"023b8ca9-d11f-4634-87a6-f03ba5d483b1","p1MaxCents":700000,"p1MinCents":300000,"p2MaxCents":300000,"p2MinCents":120000,"p3MaxCents":75000,"p3MinCents":55000,"p4MaxCents":25000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eTarget Overview\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eThis is a browser-based version of \u003ca href=\"https://www.mathworks.com/products/matlab.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eMATLAB\u003c/a\u003e. This platform gives users a MATLAB experience in a browser. As such, it is \u003cem\u003edesigned to execute user-supplied MATLAB code\u003c/em\u003e. This includes OS commands using the \u003ca href=\"https://www.mathworks.com/help/matlab/ref/system.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003esystem()\u003c/a\u003e or \u003ca href=\"https://www.mathworks.com/help/matlab/internet-file-access.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003enetwork enabled functions\u003c/a\u003e in MATLAB. Executing MATLAB commands at the prompt or within a MATLAB program does not meet the standard for any \u0026quot;Server-Side Injection\u0026quot; vulnerabilities. We are interested in vulnerabilities that allow a user to execute commands as a privileged (root) user.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMATLAB Online runs in a Docker container on a Linux host running in Amazon EC2. We are particularly interested in any vulnerabilities that allow a user to escape from the Docker container to the host operating system. The production environment for MATLAB Online is \u003ca href=\"https://matlab.mathworks.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://matlab.mathworks.com/\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMATLAB Online has several features that contact MathWorks. For example, \u0026quot;Send feedback\u0026quot;. Do not use these features to contact MathWorks staff.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":3000,"max":7000},"2":{"min":1200,"max":3000},"3":{"min":550,"max":750},"4":{"min":200,"max":250},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"22e006a9-8881-4500-97b6-ccf09ead9904","code":"matlab-online","state":"in_progress","endsAt":null,"bountyId":"56c0c575-f8e6-4808-b5e1-678b1a85ed60","startsAt":"2026-05-06T14:01:15Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/9f5f/287d/7fe37911/dd30d37fbd1f9c2cb76698ea65a170cf_MathWorks-Logo.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-07-28T15:59:14.508Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/matlab-online","changelogs":"/engagements/matlab-online/changelog","submissions":null,"announcements":"/engagements/matlab-online/announcements","hallOfFame":"/engagements/matlab-online/hall_of_fames","crowdstream":null},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/matlab-online/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=matlab-online\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/matlab-online/engagement_subscribers","engagementChangelogsUrl":"/engagements/matlab-online/changelog","publishedAt":"2026-09-03T15:56:33.843Z","engagementChangelogUrl":"/engagements/matlab-online/changelog/6b90f7f3-355b-406d-848e-3dfb0622f02a","createUserFeedbacksUrl":"/engagements/matlab-online/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}