{"id":"75a59b74-de1b-4378-9e3a-bdc83286825d","engagementId":"ebbe535d-b853-48d5-99f4-a14c97487bf6","data":{"brief":{"id":"62bbc787-d337-418a-8679-3ff432ec05a6","name":"Navan","tagline":"Help secure Navan","description":"\u003ch2\u003e1. Welcome\u003c/h2\u003e\n\n\u003cp\u003eDiscover the magic of Navan: Business Software Designed for People.\u003c/p\u003e\n\n\u003cp\u003eNo technology is perfect, and Navan believes that working with skilled security researchers around the globe is crucial for identifying weaknesses. We are excited to have you participate as a security researcher and help us identify vulnerabilities in our assets.\u003c/p\u003e\n\n\u003cp\u003eGood luck, and happy hunting!\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e2. Program Scope \u0026amp; Targets\u003c/h2\u003e\n\n\u003cp\u003eTo continue participating in the program, you may:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eJoin the company on Bugcrowd, or\u003c/li\u003e\n\u003cli\u003eCreate a new company account through our self-service sign-up in production: \u003ca href=\"https://navan.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://navan.com\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eAll guidance below applies to testing in production at:\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://app.navan.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://app.navan.com\u003c/a\u003e\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eTesting is only authorized on targets listed as \u003cstrong\u003ein scope\u003c/strong\u003e in the Bugcrowd program brief.\u003c/li\u003e\n\u003cli\u003eAny Navan domain/property \u003cstrong\u003enot\u003c/strong\u003e listed as in scope is \u003cstrong\u003eout of scope\u003c/strong\u003e. This includes any/all subdomains not explicitly listed.\u003c/li\u003e\n\u003cli\u003eIf you identify a vulnerability on a target that is not in scope but clearly belongs to Navan, you may submit it:\n\n\u003cul\u003e\n\u003cli\u003eIt will be reviewed for awareness and remediation.\u003c/li\u003e\n\u003cli\u003eIt will \u003cstrong\u003enot\u003c/strong\u003e be eligible for rewards or points-based compensation.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eAlways refer to the \u003cstrong\u003elive Bugcrowd program page\u003c/strong\u003e for the authoritative, current scope.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003ePrimary app:\u003c/strong\u003e \u003ca href=\"https://app.navan.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://app.navan.com\u003c/a\u003e  \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e3. Access \u0026amp; Account Creation (Production)\u003c/h2\u003e\n\n\u003ch3\u003e3.1 Primary URL\u003c/h3\u003e\n\n\u003cp\u003eAll testing is conducted on:\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://app.navan.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://app.navan.com\u003c/a\u003e\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch3\u003e3.2 Two options for access\u003c/h3\u003e\n\n\u003cp\u003eYou can access Navan in production in two ways:\u003c/p\u003e\n\n\u003ch4\u003eOption A – Private Self-Service Sign-up Environment\u003c/h4\u003e\n\n\u003cp\u003eSign up a new company in production. Use this if you want a \u003cstrong\u003eprivate, isolated\u003c/strong\u003e environment where no other test users exist.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eRequirements:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou will need your \u003cstrong\u003eown domain\u003c/strong\u003e (e.g. \u003ccode\u003eexample-bc-test.com\u003c/code\u003e). \u003c/li\u003e\n\u003cli\u003eYou must have \u003cstrong\u003eemail addresses on that domain\u003c/strong\u003e for your test users (e.g. \u003ccode\u003euser1@example-bc-test.com\u003c/code\u003e). \u003c/li\u003e\n\u003cli\u003eYou \u003cstrong\u003eMUST\u003c/strong\u003e use first and last name as test.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCompany name must be in the following format “Bugcrowd-randomString123”.\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eSign-up steps:\u003c/strong\u003e\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eGo to: \u003cstrong\u003e\u003ca href=\"https://navan.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://navan.com\u003c/a\u003e\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eUse the tile \u003cstrong\u003e“Create a company travel program”\u003c/strong\u003e → click \u003cstrong\u003eGet started\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eOn the next screen, add a \u003cstrong\u003etest email\u003c/strong\u003e. You need to have a \u003cstrong\u003ereal inbox\u003c/strong\u003e on an address; use \u003cstrong\u003eBugcrowd\u003c/strong\u003e + some random string so \u003cstrong\u003eeach tester has a unique\u003c/strong\u003e address).\u003c/li\u003e\n\u003cli\u003eClick \u003cstrong\u003eContinue with email\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eCheck the inbox for an email titled \u003cstrong\u003e“Verify your email to start using Navan”\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eClick \u003cstrong\u003eVerify email\u003c/strong\u003e → the sign-up form opens.\u003c/li\u003e\n\u003cli\u003eFill the form as follows:\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eFirst name and last name:\u003c/strong\u003e you \u003cstrong\u003emust\u003c/strong\u003e use \u003cstrong\u003eTest\u003c/strong\u003e / \u003cstrong\u003eTest\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCompany name:\u003c/strong\u003e use \u003cstrong\u003eBugcrowd-randomString123\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAnnual travel budget:\u003c/strong\u003e \u003cstrong\u003e0–50K\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eOther fields:\u003c/strong\u003e as you wish.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eWhen all fields are filled → click \u003cstrong\u003eCreate account\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eOn the following page → click \u003cstrong\u003eStart company setup\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eYou should be logged into the app (e.g. you see the \u003cstrong\u003eHome\u003c/strong\u003e screen).\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003e\u003cstrong\u003eThis gives you:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eA private production testing environment that you fully control.\u003c/li\u003e\n\u003cli\u003eNo other Bugcrowd researchers in that company by default, so you can freely test without worrying about interfering with others.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eYou may still use your \u003ccode\u003e@bugcrowdninja.com\u003c/code\u003e email for Bugcrowd-related communication, but the Navan environment itself can be tied to your own test domain and mailboxes.\u003c/p\u003e\n\n\u003ch4\u003eOption B – Shared Bugcrowdninja Sandbox Company\u003c/h4\u003e\n\n\u003cp\u003eUse this if you’re comfortable \u003cstrong\u003esharing an environment\u003c/strong\u003e with other researchers.\u003c/p\u003e\n\n\u003cp\u003eThis Bugcrowdninja company is a \u003cstrong\u003eshared environment\u003c/strong\u003e used by multiple researchers.\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eContact the \u003cstrong\u003eBugcrowd triage team\u003c/strong\u003e through the Bugcrowd platform.\u003c/li\u003e\n\u003cli\u003eRequest a Navan production sandbox test account for \u003ca href=\"https://app.navan.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://app.navan.com\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eYou \u003cstrong\u003emust\u003c/strong\u003e use an email address on the \u003cstrong\u003e\u003ccode\u003e@bugcrowdninja.com\u003c/code\u003e\u003c/strong\u003e domain.\n\n\u003cul\u003e\n\u003cli\u003eOnly \u003ccode\u003e@bugcrowdninja.com\u003c/code\u003e emails are allowed for these shared test accounts.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003eTriagers use admin + delegate accounts to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCreate a user for you in the shared sandbox company.\u003c/li\u003e\n\u003cli\u003eAssign roles as needed (e.g. Traveler, Travel Admin, Expense Admin).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e4. Shared Sandbox Company Overview (Bugcrowdninja Option)\u003c/h2\u003e\n\n\u003cp\u003eIf you choose the shared Bugcrowdninja company route (\u003cstrong\u003eOption B\u003c/strong\u003e):\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAll researchers share the same test company on \u003ccode\u003eapp.navan.com\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThis company is divided into:\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ea. Travel\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eb. Expense\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eImplications:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eTrips, expenses, users, and settings may be created or used by other researchers.\u003c/li\u003e\n\u003cli\u003eYour changes can affect their tests, so \u003cstrong\u003eshared-environment rules apply\u003c/strong\u003e (see Section 9).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eIf you use \u003cstrong\u003eself-signup\u003c/strong\u003e (\u003cstrong\u003eOption A\u003c/strong\u003e), you will have \u003cstrong\u003eyour own company\u003c/strong\u003e and do \u003cstrong\u003enot\u003c/strong\u003e share data with other researchers in that environment.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e5. Travel Functionality\u003c/h2\u003e\n\n\u003cp\u003eThe Travel area supports booking and managing business trips.\u003c/p\u003e\n\n\u003cp\u003eYou can test functionality such as:\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eBooking:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eFlights\u003c/li\u003e\n\u003cli\u003eHotels\u003c/li\u003e\n\u003cli\u003eTrains\u003c/li\u003e\n\u003cli\u003eCar rentals\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eManaging trips:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eViewing itineraries\u003c/li\u003e\n\u003cli\u003eModifying or canceling segments (where allowed)\u003c/li\u003e\n\u003cli\u003eInviting guests to trips and managing guest details\u003c/li\u003e\n\u003cli\u003eAny other travel-related features visible in the UI\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eYou are encouraged to explore these flows within scope, while following shared-environment rules if using the Bugcrowdninja company.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e6. Expense Functionality\u003c/h2\u003e\n\n\u003cp\u003eThe Expense area focuses on submitting and managing travel-related and business expenses.\u003c/p\u003e\n\n\u003cp\u003eYou can test functionality such as:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCreating expenses and attaching receipts\u003c/li\u003e\n\u003cli\u003eSubmitting expense reports for approval\u003c/li\u003e\n\u003cli\u003eManaging expenses that may be tied to:\n\n\u003cul\u003e\n\u003cli\u003eNavan corporate card transactions (if configured/visible)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eReviewing policies and approval workflows available to your roles\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eAgain, treat existing data as potentially belonging to others if you’re in the shared Bugcrowdninja company.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e7. Roles and Permissions\u003c/h2\u003e\n\n\u003cp\u003eMany features are role-based. Common roles include:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eTravel Admin\u003c/li\u003e\n\u003cli\u003eExpense Admin\u003c/li\u003e\n\u003cli\u003eTraveler\u003c/li\u003e\n\u003cli\u003eOther internal roles as configured\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eYour roles determine what you can access and perform.\u003c/p\u003e\n\n\u003ch3\u003e7.1 Requesting roles / additional test accounts\u003c/h3\u003e\n\n\u003cp\u003eTo test role-based behavior:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eVia Bugcrowdninja (shared):\u003c/strong\u003e Ask Bugcrowd triagers to create more test accounts or adjust roles for you.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eVia self-signup (private):\u003c/strong\u003e Use your own admin account to create additional test users on your own domain and assign roles yourself.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eDo not\u003c/strong\u003e permanently alter other users’ roles in the shared environment. If you discover a privilege escalation or cross-account access, \u003cstrong\u003estop and report it\u003c/strong\u003e.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e8. Shared Environment Rules (Bugcrowdninja Company)\u003c/h2\u003e\n\n\u003cp\u003eThese rules apply \u003cstrong\u003eonly\u003c/strong\u003e when using the shared Bugcrowdninja company (\u003cstrong\u003eOption B\u003c/strong\u003e).\u003c/p\u003e\n\n\u003cp\u003eIn your \u003cstrong\u003eprivate self-signup\u003c/strong\u003e environment (\u003cstrong\u003eOption A\u003c/strong\u003e), you can freely modify your own company.\u003c/p\u003e\n\n\u003ch3\u003e8.1 Respect other researchers’ data\u003c/h3\u003e\n\n\u003cp\u003eAssume that any user, trip, expense, or configuration you did not clearly create yourself may:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eBelong to another researcher, or\u003c/li\u003e\n\u003cli\u003eBe used for another test scenario.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eAvoid:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDeleting or overwriting other researchers’ data.\u003c/li\u003e\n\u003cli\u003eMaking large, global configuration changes.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003e8.2 Destructive actions\u003c/h3\u003e\n\n\u003cp\u003eYou should test fully within scope, but be very careful with \u003cstrong\u003edestructive\u003c/strong\u003e actions, such as:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDeleting users, trips, expenses, or reports.\u003c/li\u003e\n\u003cli\u003eChanging or deleting global/company-level settings and policies.\u003c/li\u003e\n\u003cli\u003ePerforming bulk or mass operations.\u003c/li\u003e\n\u003cli\u003eActions labeled: \u003cstrong\u003eDelete / Remove / Purge\u003c/strong\u003e, \u003cstrong\u003eReset\u003c/strong\u003e, \u003cstrong\u003eClose / Terminate / Cancel\u003c/strong\u003e (user or company level).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eBest practice in shared environment:\u003c/strong\u003e Perform destructive tests only on data you clearly own. For example:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eUser: \u003ccode\u003eBC-\u0026lt;your_handle\u0026gt;-User1\u003c/code\u003e\n\u003c/li\u003e\n\u003cli\u003eTrip: \u003ccode\u003eBC-\u0026lt;your_handle\u0026gt;-Trip1\u003c/code\u003e\n\u003c/li\u003e\n\u003cli\u003eExpense Report: \u003ccode\u003eBC-\u0026lt;your_handle\u0026gt;-Expenses1\u003c/code\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eIn your \u003cstrong\u003eself-signup private\u003c/strong\u003e environment, you can safely perform destructive tests on your own company data, as no other researchers share it.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e9. Test Data \u0026amp; Privacy Requirements\u003c/h2\u003e\n\n\u003cp\u003eRegardless of whether you’re using Bugcrowdninja or self-signup:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eDo not\u003c/strong\u003e use real personal or financial information.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eProhibited:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eReal PII:\u003c/strong\u003e real home addresses, real passport/ID numbers, real personal phone numbers (beyond minimal, non-sensitive test data).\u003c/li\u003e\n\u003cli\u003eReal credit card or bank account details.\u003c/li\u003e\n\u003cli\u003eAny confidential data you would not want exposed.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eUse only dummy/test data\u003c/strong\u003e for names, contact details, payment information, and document numbers.\u003c/p\u003e\n\n\u003cp\u003eEven in private self-signup environments, we recommend using only test data.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e10. Test Credit Card Details\u003c/h2\u003e\n\n\u003cp\u003eFor testing payment flows and booking:\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eField\u003c/th\u003e\n\u003cth\u003eValue\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eBrand\u003c/td\u003e\n\u003ctd\u003eVisa\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eCard Number\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e4242 4242 4242 4242\u003c/code\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eExpiration Date\u003c/td\u003e\n\u003ctd\u003eAny future date\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eCVV\u003c/td\u003e\n\u003ctd\u003eAny 3 digits\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003cp\u003eMore test credit card information: \u003ca href=\"https://docs.stripe.com/testing\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eStripe testing documentation\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003eUse this test card only in test/payment flows designed for it. Additional test card information may be provided in the Bugcrowd brief or Navan docs.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e11. Focus Areas\u003c/h2\u003e\n\n\u003cp\u003eWe are especially interested in:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eTravel and Expense \u003cstrong\u003eend-user and Admin\u003c/strong\u003e applications.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePII exposure\u003c/strong\u003e, particularly \u003cstrong\u003ecross-tenant PII exposure\u003c/strong\u003e:\n\n\u003cul\u003e\n\u003cli\u003eSome PII may legitimately be visible for booking on behalf of others.\u003c/li\u003e\n\u003cli\u003eHowever, it should be appropriately limited and controlled.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eFindings around \u003cstrong\u003eimproper PII access\u003c/strong\u003e or \u003cstrong\u003ecross-tenant leakage\u003c/strong\u003e are high-value.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e12. Ratings, Rewards \u0026amp; Domain Reimbursement\u003c/h2\u003e\n\n\u003ch3\u003e12.1 Ratings \u0026amp; rewards\u003c/h3\u003e\n\n\u003cp\u003eFor initial prioritization and rating of findings, we use the \u003cstrong\u003eBugcrowd Vulnerability Rating Taxonomy (VRT)\u003c/strong\u003e as a baseline:\u003cbr\u003e\u003cbr\u003e\n\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://bugcrowd.com/vulnerability-rating-taxonomy\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003eUsed for:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eInitial severity rating\u003c/li\u003e\n\u003cli\u003eInitial reward determination\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eHowever:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSeverity may be adjusted up or down based on actual impact and likelihood in Navan’s environment.\u003c/li\u003e\n\u003cli\u003eIf an issue is downgraded, we will:\n\n\u003cul\u003e\n\u003cli\u003eProvide a detailed explanation.\u003c/li\u003e\n\u003cli\u003eOffer you an opportunity to appeal and make a case for a higher rating.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eReward ranges:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePublished ranges are \u003cstrong\u003eguidelines\u003c/strong\u003e, not hard caps.\u003c/li\u003e\n\u003cli\u003eWe may pay \u003cstrong\u003eabove\u003c/strong\u003e the listed ranges if we believe a vulnerability poses a higher risk than anticipated.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003e12.2 Domain registration reimbursement\u003c/h3\u003e\n\n\u003cp\u003eFor research that requires you to register a domain (especially relevant for self-signup private environments):\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eUse an existing domain if you have one.\u003c/li\u003e\n\u003cli\u003eIf you already own a domain that you can reasonably use for testing, you should use that domain instead of registering a new one specifically for this program.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eNavan will \u003cstrong\u003ereimburse standard domain registration fees\u003c/strong\u003e for any \u003cstrong\u003evalid report\u003c/strong\u003e that requires such registration. This applies both to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDomains needed to provision your own self-signup production environment, and\u003c/li\u003e\n\u003cli\u003eDomains needed for vulnerability scenarios (e.g. email spoofing, redirect targets).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eOne-time reimbursement per researcher.\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eIf you qualify for a domain reimbursement, it will be a \u003cstrong\u003eone-time payment\u003c/strong\u003e for a domain associated with a \u003cstrong\u003evalid, non-duplicate\u003c/strong\u003e submission.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOnly \u003cstrong\u003eone\u003c/strong\u003e domain reimbursement is allowed per researcher, after a valid, non-duplicate submission is accepted.\u003c/li\u003e\n\u003cli\u003eCoordinate reimbursement details through \u003cstrong\u003eBugcrowd triage\u003c/strong\u003e as part of the report process.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e13. Automated Tooling Requirements\u003c/h2\u003e\n\n\u003cp\u003eWhen using automated tools (scanners, fuzzers, scripts, etc.) against Navan:\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eEvery request\u003c/strong\u003e from automated tooling must include this HTTP header:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre class=\"highlight http\"\u003e\u003ccode\u003e\u003cspan class=\"err\"\u003eX-Bugcrowd-Id: \u0026lt;your_bugcrowd_username\u0026gt;\n\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cp\u003eWhere \u003ccode\u003e\u0026lt;your_bugcrowd_username\u0026gt;\u003c/code\u003e is your Bugcrowd handle.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eImportant:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eRequests from automated tools \u003cstrong\u003ewithout\u003c/strong\u003e this header may be blocked.\u003c/li\u003e\n\u003cli\u003eSuch requests may \u003cstrong\u003enot\u003c/strong\u003e qualify for safe harbor protections under the program.\u003c/li\u003e\n\u003cli\u003eEnsure your tooling is configured to \u003cstrong\u003ealways\u003c/strong\u003e set this header.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e14. Quality Submissions\u003c/h2\u003e\n\n\u003cp\u003eHigh-quality reports:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eTriage faster.\u003c/li\u003e\n\u003cli\u003eAre more likely to get accurate severities and rewards.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eTo help us reproduce and assess issues quickly:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eInclude \u003cstrong\u003ecomplete HTTP requests\u003c/strong\u003e for key steps.\u003c/li\u003e\n\u003cli\u003eInclude \u003cstrong\u003evalid JWT tokens\u003c/strong\u003e (or relevant authorization material) where appropriate:\n\n\u003cul\u003e\n\u003cli\u003eThis clarifies the assumed access model.\u003c/li\u003e\n\u003cli\u003eIt allows efficient internal replication.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eAvoid sharing unnecessary secrets, and use Bugcrowd’s secure channels for sensitive material.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e15. Prohibited Activities \u0026amp; Disclosure\u003c/h2\u003e\n\n\u003cp\u003eResearchers are \u003cstrong\u003enot\u003c/strong\u003e allowed to:\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003ePerform \u003cstrong\u003edenial-of-service\u003c/strong\u003e attacks, including \u003cstrong\u003edistributed denial-of-service (DDoS)\u003c/strong\u003e attacks, traffic flooding, or any other activity intended to degrade or disrupt the availability or performance of Navan services.\u003c/li\u003e\n\u003cli\u003eUse \u003cstrong\u003eautomated scanners\u003c/strong\u003e or other automated tooling \u003cstrong\u003eunless\u003c/strong\u003e explicitly permitted by the Bugcrowd program brief and/or \u003cstrong\u003epre-approved\u003c/strong\u003e by Navan (via Bugcrowd triage). If automated tooling is permitted, it must comply with \u003cstrong\u003eSection 13\u003c/strong\u003e and include the required \u003ccode\u003eX-Bugcrowd-Id\u003c/code\u003e header on every request.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePublicly disclose\u003c/strong\u003e vulnerabilities, exploit details, or any findings related to this program without Navan’s \u003cstrong\u003eprior written approval\u003c/strong\u003e, and you must follow Bugcrowd’s disclosure guidelines.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e16. Safe Harbor\u003c/h2\u003e\n\n\u003cp\u003eIf you follow this policy and the Bugcrowd program rules, Navan considers your research to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized under the \u003cstrong\u003eCFAA\u003c/strong\u003e and similar state laws.\u003c/li\u003e\n\u003cli\u003eWe will \u003cstrong\u003enot\u003c/strong\u003e initiate or support legal action against you for accidental, good-faith violations of this policy.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eExempt from the DMCA\u003c/strong\u003e for circumvention done in the course of legitimate, good-faith security testing under this policy.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eExempt from conflicting Terms \u0026amp; Conditions\u003c/strong\u003e that would otherwise restrict security research, on a limited basis for this work.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eLawful, good-faith research\u003c/strong\u003e that benefits Navan and Internet security.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eYou are still responsible for complying with \u003cstrong\u003eall applicable laws\u003c/strong\u003e.\u003c/p\u003e\n\n\u003cp\u003eIf you are ever unsure whether your activity is allowed:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOpen a ticket with \u003cstrong\u003eBugcrowd Support\u003c/strong\u003e and ask for clarification \u003cstrong\u003ebefore\u003c/strong\u003e proceeding.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e17. Questions \u0026amp; Support\u003c/h2\u003e\n\n\u003cp\u003eContact the \u003cstrong\u003eBugcrowd triage team\u003c/strong\u003e via the Bugcrowd platform for:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eScope questions (in-scope vs out-of-scope).\u003c/li\u003e\n\u003cli\u003eAccess issues for \u003ca href=\"https://app.navan.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://app.navan.com\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eProblems with your test account or roles.\u003c/li\u003e\n\u003cli\u003eRequests for additional test accounts (shared or private).\u003c/li\u003e\n\u003cli\u003eQuestions about destructive testing in the shared Bugcrowdninja company.\u003c/li\u003e\n\u003cli\u003eClarification about staging decommissioning and production migration.\u003c/li\u003e\n\u003cli\u003eDetails on domain registration reimbursement for valid reports.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eWe appreciate your continued engagement and look forward to your ongoing research in the \u003cstrong\u003eproduction\u003c/strong\u003e environment.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003e\u003cem\u003eConverted from the updated Navan Bugcrowd researcher guide PDF. Option labels in §4 and §8 of the PDF are inconsistent with §3; this document uses **Option A = private self-signup\u003c/em\u003e\u003cem\u003e, **Option B = shared Bugcrowdninja\u003c/em\u003e* throughout.*\u003c/p\u003e","industryTagId":"0e55e259-dfc5-4952-99de-5e094e40609a","targetsOverview":"\u003ch2\u003e1. Program Scope \u0026amp; Targets\u003c/h2\u003e\n\n\u003cp\u003eTo continue participating in the program, you may:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eJoin the company on Bugcrowd, or\u003c/li\u003e\n\u003cli\u003eCreate a new company account through our self-service sign-up in production: \u003ca href=\"https://navan.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://navan.com\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eAll guidance below applies to testing in production at:\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://app.navan.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://app.navan.com\u003c/a\u003e\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eTesting is only authorized on targets listed as \u003cstrong\u003ein scope\u003c/strong\u003e in the Bugcrowd program brief.\u003c/li\u003e\n\u003cli\u003eAny Navan domain/property \u003cstrong\u003enot\u003c/strong\u003e listed as in scope is \u003cstrong\u003eout of scope\u003c/strong\u003e. This includes any/all subdomains not explicitly listed.\u003c/li\u003e\n\u003cli\u003eIf you identify a vulnerability on a target that is not in scope but clearly belongs to Navan, you may submit it:\n\n\u003cul\u003e\n\u003cli\u003eIt will be reviewed for awareness and remediation.\u003c/li\u003e\n\u003cli\u003eIt will \u003cstrong\u003enot\u003c/strong\u003e be eligible for rewards or points-based compensation.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eAlways refer to the \u003cstrong\u003elive Bugcrowd program page\u003c/strong\u003e for the authoritative, current scope.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003ePrimary app:\u003c/strong\u003e \u003ca href=\"https://app.navan.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://app.navan.com\u003c/a\u003e\u003cbr\u003e\u003cbr\u003e\n\u003cstrong\u003eResearcher email domain:\u003c/strong\u003e \u003ccode\u003ebugcrowdninja.com\u003c/code\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e2. Test Credit Card Details\u003c/h2\u003e\n\n\u003cp\u003eFor testing payment flows and booking:\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eField\u003c/th\u003e\n\u003cth\u003eValue\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eBrand\u003c/td\u003e\n\u003ctd\u003eVisa\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eCard Number\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e4242 4242 4242 4242\u003c/code\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eExpiration Date\u003c/td\u003e\n\u003ctd\u003eAny future date\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eCVV\u003c/td\u003e\n\u003ctd\u003eAny 3 digits\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003cp\u003eMore test credit card information: \u003ca href=\"https://docs.stripe.com/testing\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eStripe testing documentation\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003eUse this test card only in test/payment flows designed for it. Additional test card information may be provided in the Bugcrowd brief or Navan docs.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e3. Access \u0026amp; Account Creation (Production)\u003c/h2\u003e\n\n\u003ch3\u003e3.1 Primary URL\u003c/h3\u003e\n\n\u003cp\u003eAll testing is conducted on:\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://app.navan.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://app.navan.com\u003c/a\u003e\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch3\u003e3.2 Two options for access\u003c/h3\u003e\n\n\u003cp\u003eYou can access Navan in production in two ways:\u003c/p\u003e\n\n\u003ch4\u003eOption A – Private Self-Service Sign-up Environment\u003c/h4\u003e\n\n\u003cp\u003eSign up a new company in production. Use this if you want a \u003cstrong\u003eprivate, isolated\u003c/strong\u003e environment where no other test users exist.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eRequirements:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou will need your \u003cstrong\u003eown domain\u003c/strong\u003e (e.g. \u003ccode\u003eexample-bc-test.com\u003c/code\u003e). \u003cstrong\u003eIf you do not have one or cannot create one\u003c/strong\u003e, use a \u003cstrong\u003efake domain name\u003c/strong\u003e that contains \u003cstrong\u003e“bugcrowd”\u003c/strong\u003e in the domain name (e.g. \u003ccode\u003ebugcrowdninja-hunt1.com\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eYou must have \u003cstrong\u003eemail addresses on that domain\u003c/strong\u003e for your test users (e.g. \u003ccode\u003euser1@example-bc-test.com\u003c/code\u003e). If you used a \u003cstrong\u003efake domain\u003c/strong\u003e (e.g. \u003ccode\u003ebugcrowdninja-hunt1.com\u003c/code\u003e), ensure you create a profile with \u003cstrong\u003e“test”\u003c/strong\u003e as \u003cstrong\u003efirst AND last name\u003c/strong\u003e for this to work.\u003c/li\u003e\n\u003cli\u003eThey \u003cstrong\u003eMUST\u003c/strong\u003e use first and last name as test.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCompany name must contain “bugcrowd”.\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eSign-up steps:\u003c/strong\u003e\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eGo to: \u003cstrong\u003e\u003ca href=\"https://navan.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://navan.com\u003c/a\u003e\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eUse the tile \u003cstrong\u003e“Create a company travel program”\u003c/strong\u003e → click \u003cstrong\u003eGet started\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eOn the next screen, add a \u003cstrong\u003etest email\u003c/strong\u003e. You need to have a \u003cstrong\u003ereal inbox\u003c/strong\u003e on an address whose domain includes the word \u003cstrong\u003e“Bugcrowd”\u003c/strong\u003e (e.g. a domain you control that contains that word — \u003cstrong\u003enot\u003c/strong\u003e the literal example email from the guide; use \u003cstrong\u003eBugcrowd\u003c/strong\u003e + some random string so \u003cstrong\u003eeach tester has a unique\u003c/strong\u003e address).\u003c/li\u003e\n\u003cli\u003eClick \u003cstrong\u003eContinue with email\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eCheck the inbox for an email titled \u003cstrong\u003e“Verify your email to start using Navan”\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eClick \u003cstrong\u003eVerify email\u003c/strong\u003e → the sign-up form opens.\u003c/li\u003e\n\u003cli\u003eFill the form as follows:\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eFirst name and last name:\u003c/strong\u003e you \u003cstrong\u003emust\u003c/strong\u003e use \u003cstrong\u003eTest\u003c/strong\u003e / \u003cstrong\u003eTest\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCompany name:\u003c/strong\u003e use \u003cstrong\u003eBugcrowd\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAnnual travel budget:\u003c/strong\u003e \u003cstrong\u003e0–50K\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eOther fields:\u003c/strong\u003e as you wish.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eWhen all fields are filled → click \u003cstrong\u003eCreate account\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eOn the following page → click \u003cstrong\u003eStart company setup\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eYou should be logged into the app (e.g. you see the \u003cstrong\u003eHome\u003c/strong\u003e screen).\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003e\u003cstrong\u003eThis gives you:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eA private production testing environment that you fully control.\u003c/li\u003e\n\u003cli\u003eNo other Bugcrowd researchers in that company by default, so you can freely test without worrying about interfering with others.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eYou may still use your \u003ccode\u003e@bugcrowdninja.com\u003c/code\u003e email for Bugcrowd-related communication, but the Navan environment itself can be tied to your own test domain and mailboxes.\u003c/p\u003e\n\n\u003ch4\u003eOption B – Shared Bugcrowdninja Sandbox Company\u003c/h4\u003e\n\n\u003cp\u003eUse this if you’re comfortable \u003cstrong\u003esharing an environment\u003c/strong\u003e with other researchers.\u003c/p\u003e\n\n\u003cp\u003eThis Bugcrowdninja company is a \u003cstrong\u003eshared environment\u003c/strong\u003e used by multiple researchers.\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eContact the \u003cstrong\u003eBugcrowd triage team\u003c/strong\u003e through the Bugcrowd platform.\u003c/li\u003e\n\u003cli\u003eRequest a Navan production sandbox test account for \u003ca href=\"https://app.navan.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://app.navan.com\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eYou \u003cstrong\u003emust\u003c/strong\u003e use an email address on the \u003cstrong\u003e\u003ccode\u003e@bugcrowdninja.com\u003c/code\u003e\u003c/strong\u003e domain.\n\n\u003cul\u003e\n\u003cli\u003eOnly \u003ccode\u003e@bugcrowdninja.com\u003c/code\u003e emails are allowed for these shared test accounts.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003eTriagers use admin + delegate accounts to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCreate a user for you in the shared sandbox company.\u003c/li\u003e\n\u003cli\u003eAssign roles as needed (e.g. Traveler, Travel Admin, Expense Admin).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eTravel and Expense end user and Admin applications\u003c/li\u003e\n\u003cli\u003ePII exposure, particularly cross tenant PII exposure. Note that some PII needs to be shared for people booking for other people, but it should still be limited.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eRate Limiting\u003c/li\u003e\n\u003cli\u003eDistributed Denial of Service (DDos)\u003c/li\u003e\n\u003cli\u003eSelf-DoS issues (as in, only the person doing the action is denied service).\u003c/li\u003e\n\u003cli\u003eClickjacking, which involves manipulating user interfaces\u003c/li\u003e\n\u003cli\u003eAbsence of or invalid SPF records\u003c/li\u003e\n\u003cli\u003eUnauthorized access to our Atlassian Service Desk\u003c/li\u003e\n\u003cli\u003eGoogle API Key Disclosures\u003c/li\u003e\n\u003cli\u003eEnumerating email addresses through login attempts.\u003c/li\u003e\n\u003cli\u003eExpiration of password reset links.\u003c/li\u003e\n\u003cli\u003eDomain Takeover via Available S3 .tripactions.com Buckets\u003c/li\u003e\n\u003cli\u003eReports related to the disclosure of Exif metadata from uploaded files\u003c/li\u003e\n\u003cli\u003eReports related to third-party components, like chat services, are excluded from this bug bounty program's scope\u003c/li\u003e\n\u003cli\u003eReports related to weak SSL ciphers, which are a part of the broader SSL configuration\u003c/li\u003e\n\u003cli\u003eReports related to the sign-up process using your bugcrowdninja email address - this process was created to facilitate testing and doesn’t reflect actual product behaviour\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eQuality Submissions:\u003c/h2\u003e\n\n\u003cp\u003eSubmitting high-quality vulnerability reports is crucial for ensuring faster processing times and increasing the chances of receiving rewards. To facilitate quick replication and assessment of the reported vulnerability:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eIt is important to provide complete HTTP requests, including valid JWT tokens. These tokens help in understanding the assumed access model and enable efficient investigation and validation of the vulnerability. By including all necessary information, submitters can contribute to a smoother and more efficient vulnerability assessment process.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ecreate a ticket with Bugcrowd Support\u003c/a\u003e for clarification before proceeding.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"9b034421-adf8-4480-896e-723fb7dae4dc","name":"In Scope","targets":[{"id":"f3cbddfb-aa45-4062-b3d7-a2dee197c82b","uri":"https://app.navan.com","name":"https://app.navan.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"b91a64ea-133c-4ea4-b735-d58e8bf5b4f1","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"f3cbddfb-aa45-4062-b3d7-a2dee197c82b"},{"id":"ad43847d-d5ec-4d65-a1f1-8f20ec7e9238","name":"Penetration Testing","targetId":"f3cbddfb-aa45-4062-b3d7-a2dee197c82b"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f3cbddfb-aa45-4062-b3d7-a2dee197c82b"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"6b8d240e-e19d-411b-8ba0-c21a7fb19032","p1MaxCents":450000,"p1MinCents":210000,"p2MaxCents":250000,"p2MinCents":100000,"p3MaxCents":100000,"p3MinCents":45000,"p4MaxCents":100000,"p4MinCents":15000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eNavan is a platform that companies use to manage employee travel and expenses from a single portal. They welcome testing on their services as to help find security vulnerabilities to ensure the users of their platform are secure. In particular, there are a number of roles (admin, user, guest, etc.) that the Navan team is interested in understanding access control issues around.\u003c/p\u003e","rewardRangeData":{"1":{"min":2100,"max":4500},"2":{"min":1000,"max":2500},"3":{"min":450,"max":1000},"4":{"min":150,"max":1000},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"a903cf56-30a6-4143-9b12-02ccc74f0075","name":"Out of Scope","targets":[{"id":"f452fdeb-76b6-4ed9-ae26-943c344634a3","uri":"","name":"tripactions.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"52090867-af04-4a85-8e5a-2b760d2f02c6","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"ebbe535d-b853-48d5-99f4-a14c97487bf6","code":"navan","state":"in_progress","endsAt":null,"bountyId":"012e7bcd-15ff-4a89-9691-7e7889c15504","startsAt":"2021-03-18T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Business Management","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/3ce8/de68/8ad252f6/2bc8ac2897c30967ca7b833715c65e1c_Navan_App_Icon.png","logoBackgroundColor":"#5F00C0","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-04-30T16:37:58.143Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/navan","changelogs":"/engagements/navan/changelog","submissions":null,"announcements":"/engagements/navan/announcements","hallOfFame":"/engagements/navan/hall_of_fames","crowdstream":"/engagements/navan/crowdstream"},"announcementsCount":8,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/navan/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=navan\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/navan/engagement_subscribers","engagementChangelogsUrl":"/engagements/navan/changelog","publishedAt":"2026-04-30T16:37:58.170Z","engagementChangelogUrl":"/engagements/navan/changelog/75a59b74-de1b-4378-9e3a-bdc83286825d","createUserFeedbacksUrl":"/engagements/navan/feedbacks","engagementCrowdstreamUrl":"/engagements/navan/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}