{"id":"e6f36452-98f7-4dbf-99ab-e1cbab30fae0","engagementId":"78127e78-cb51-4b51-9339-ba981bd7850d","data":{"brief":{"id":"beb8565f-722e-462d-bb1b-17d8f5b4a18d","name":"PostHog Vulnerability Disclosure Engagement","tagline":"At PostHog, we're working to increase the number of successful products in the world.","description":"\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003eFor the initial prioritization/rating of findings, this engagement will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of PostHog not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to PostHog, you can report it to this engagement. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003ch2\u003eReport Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eReports must contain a clear explanation of the issue and the security impact along with detailed steps to reproduce it. If the issue cannot be reliably reproduced based on your report, it may be considered ineligible for a reward\u003c/li\u003e\n\u003cli\u003eDo not submit more than one vulnerability per report. In cases where demonstrating impact requires chaining multiple vulnerabilities together, those can be included in the same report as long as the linkage is clearly explained\u003c/li\u003e\n\u003cli\u003eWe do not accept reports that contain low-effort or AI-generated content. Submissions must demonstrate original analysis, clear understanding of the issue, and actionable detail. Reports lacking meaningful human input will be rejected\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eAccess\u003c/h2\u003e\n\n\u003cp\u003eThe targets within scope are publicly accessible from the internet. \u003c/p\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eImproper or missing authorization checks\u003c/li\u003e\n\u003cli\u003eInsecure role assignments or privilege escalation\u003c/li\u003e\n\u003cli\u003eAbility to access resources or perform actions outside assigned permissions\u003c/li\u003e\n\u003cli\u003eBroken access control between user types (e.g., standard user vs. admin)\u003c/li\u003e\n\u003cli\u003eSQL Editor\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cp\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 7 days has gone by\u003cbr\u003e\ne.g: N-day released on 01/01/2025, we would consider it in-scope on 01/08/2025\u003c/p\u003e\n\n\u003ch2\u003eLeaked Credentials\u003c/h2\u003e\n\n\u003cp\u003eSubmissions related to leaked or exposed credentials (e.g., dark web forums, credential dumps) will be reviewed on a case-by-case basis and may qualify for points-based compensation only. The use of any leaked credentials during testing is strictly prohibited and may result in disqualification from the bounty program.\u003c/p\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvailability/volumetric testing e.g.:\n\n\u003cul\u003e\n\u003cli\u003eDoS/DDoS/Network DoS\u003c/li\u003e\n\u003cli\u003eRate limiting bypass attempts\u003c/li\u003e\n\u003cli\u003eEmail bombing flooding\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eALL forms of social Engineering\u003c/li\u003e\n\u003cli\u003eCSRF on forms that are available to anonymous users\u003c/li\u003e\n\u003cli\u003eDisclosure of known public files or directories (e.g. robots.txt)\u003c/li\u003e\n\u003cli\u003eDNSSEC configuration suggestions\u003c/li\u003e\n\u003cli\u003eLack of Secure/HTTPOnly flags on non-sensitive cookies\u003c/li\u003e\n\u003cli\u003eLogout Cross Site Request Forgery\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affecting users who are using outdated or unpatched browsers and platforms\u003c/li\u003e\n\u003cli\u003eTesting that would result in sending spam or other unsolicited messages\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via our \u003ca href=\"https://bugcrowd-support.freshdesk.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eFreshdesk Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"0ca14326-f272-4d20-a17e-947c5c28061f","name":"In Scope","targets":[{"id":"430ea3b3-5259-4032-a050-9fbc84095662","uri":"https://us.posthog.com/","name":"https://us.posthog.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"9229764e-a0b9-46a5-ae3a-e021cfa3b42d","sortOrder":0},"sortOrder":0,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"430ea3b3-5259-4032-a050-9fbc84095662"},{"id":"84ff9b26-d234-4bba-8b77-f0f02d67d359","name":"Django","targetId":"430ea3b3-5259-4032-a050-9fbc84095662"},{"id":"95cf953e-85ee-42c2-9123-09d81bfe7ba9","name":"PostgreSQL","targetId":"430ea3b3-5259-4032-a050-9fbc84095662"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"430ea3b3-5259-4032-a050-9fbc84095662"}],"recentChangeFlags":null},{"id":"d3bb6647-d79c-42a3-aac9-9ea23a2a8323","uri":"https://posthog.com","name":"https://posthog.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"dd1e55fe-56cd-4b4b-9588-7e498655ae1e","sortOrder":1},"sortOrder":1,"tags":[{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"d3bb6647-d79c-42a3-aac9-9ea23a2a8323"}],"recentChangeFlags":null},{"id":"a809ae41-d0cd-48a9-af34-697544704c99","uri":"https://github.com/PostHog/posthog","name":"https://github.com/PostHog/posthog","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b96edd4f-23ed-4a55-b1cf-4500cef172e5","sortOrder":2},"sortOrder":2,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"a809ae41-d0cd-48a9-af34-697544704c99"},{"id":"84ff9b26-d234-4bba-8b77-f0f02d67d359","name":"Django","targetId":"a809ae41-d0cd-48a9-af34-697544704c99"},{"id":"95cf953e-85ee-42c2-9123-09d81bfe7ba9","name":"PostgreSQL","targetId":"a809ae41-d0cd-48a9-af34-697544704c99"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"a809ae41-d0cd-48a9-af34-697544704c99"}],"recentChangeFlags":null},{"id":"caf19e55-bf64-4b1c-89b4-a2cd3de17a31","uri":"https://github.com/PostHog/posthog.com","name":"https://github.com/PostHog/posthog.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"34832f30-2d8c-4b5b-b7f3-9edf2575ad1e","sortOrder":3},"sortOrder":3,"tags":[{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"caf19e55-bf64-4b1c-89b4-a2cd3de17a31"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003ch2\u003eDocumentation\u003c/h2\u003e\n\n\u003cp\u003eOur available documentation can be found \u003ca href=\"https://posthog.com/docs\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"78127e78-cb51-4b51-9339-ba981bd7850d","code":"posthog-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"da036330-71d1-4933-a076-5dd7fb6e6fb5","startsAt":"2025-09-09T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/1237/3108/d61ca298/c9b64d7d98264e5f90f45f34951cb6d9_posthog_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-09-09T18:00:00.361Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/posthog-vdp-pro","changelogs":"/engagements/posthog-vdp-pro/changelog","submissions":null,"announcements":"/engagements/posthog-vdp-pro/announcements","hallOfFame":"/engagements/posthog-vdp-pro/hall_of_fames","crowdstream":"/engagements/posthog-vdp-pro/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/posthog-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=posthog-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/posthog-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/posthog-vdp-pro/changelog","publishedAt":"2025-09-10T19:05:46.281Z","engagementChangelogUrl":"/engagements/posthog-vdp-pro/changelog/e6f36452-98f7-4dbf-99ab-e1cbab30fae0","createUserFeedbacksUrl":"/engagements/posthog-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/posthog-vdp-pro/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}