{"id":"5bb417be-b5b1-4d4c-88de-e791ed4c4138","engagementId":"f702e8dd-2c84-4a41-bbbe-1754c14dc835","data":{"brief":{"id":"03146cac-32ac-4003-a9d9-284c3b2e4735","name":"Stability AI US Services Vulnerability Disclosure Engagement","tagline":"Stability AI, a global leader in Generative AI, released Stable Diffusion in August 2022, showcasing advanced open models and professional applications for enterprise-grade visual media creation.","description":"\u003cp\u003eStability AI sparked the Generative AI revolution with the release of Stable Diffusion in August 2022, marking our position as a global leader in the field. We develop cutting-edge open models in image, video, 3D, and audio, as well as professional applications designed for enterprise-grade visual media creation.\u003c/p\u003e\n\n\u003cp\u003eNo technology is perfect and Stability AI believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our assets. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the\u003c/em\u003e \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" title=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e\u003cem\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/em\u003e\u003c/a\u003e\u003cem\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch1\u003eRules of Engagement\u003c/h1\u003e\n\n\u003cp\u003eTo ensure that good-faith security research is clearly distinguished from malicious activity, participants must follow these rules:\u003c/p\u003e\n\n\u003ch2\u003eAuthorized Testing\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou are authorized to conduct security testing only within the bounds defined by this policy.\u003c/li\u003e\n\u003cli\u003eYou must comply with this policy and all applicable agreements. In the event of any conflict, this policy takes precedence.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eCredentials\u003c/h3\u003e\n\n\u003cp\u003eTo gain access to the application(s), please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" title=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e \u003c/p\u003e\n\n\u003ch2\u003eResponsible Disclosure\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAll vulnerabilities must be reported promptly through our official \u003cstrong\u003eBugcrowd program\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eDo not disclose any information about a vulnerability to the public or third parties without \u003cstrong\u003eexplicit written permission\u003c/strong\u003e from our security team.\u003c/li\u003e\n\u003cli\u003eWe aim to authorize public disclosure within \u003cstrong\u003e90 days\u003c/strong\u003e of initial report receipt.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eProhibited Actions\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eDo not engage in activities that:\n\n\u003cul\u003e\n\u003cli\u003eCompromise privacy\u003c/li\u003e\n\u003cli\u003eDisrupt services\u003c/li\u003e\n\u003cli\u003eDestroy data\u003c/li\u003e\n\u003cli\u003eDegrade the user experience\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eDo not access, alter, or use data that does not belong to you. This includes any confidential data exposed as a result of your testing.\n\n\u003cul\u003e\n\u003cli\u003eIf such access occurs, immediately stop all testing, report the incident, and delete all related data.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eExtortion, threats, or any coercive tactics are strictly prohibited.\u003c/strong\u003e\n\n\u003cul\u003e\n\u003cli\u003eSubmissions involving coercion will \u003cstrong\u003enot\u003c/strong\u003e qualify for Safe Harbor protections.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut-of-Scope and Prohibited Testing\u003c/h2\u003e\n\n\u003cp\u003eIf you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Stability.AI, you can report it to this engagement. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003cp\u003eThe following types of activities are strictly prohibited and considered out of scope:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny test or technique that degrades availability or performance of Stability AI services without exposing a security flaw\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDenial-of-Service (DoS)\u003c/strong\u003e or \u003cstrong\u003eDistributed Denial-of-Service (DDoS)\u003c/strong\u003e attacks\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSocial engineering\u003c/strong\u003e of any kind (e.g., phishing, impersonation, manipulation of employees or contractors)\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePhysical security testing\u003c/strong\u003e (e.g., unauthorized access to facilities or hardware)\u003c/li\u003e\n\u003cli\u003eVulnerabilities in \u003cstrong\u003eexternal systems or code\u003c/strong\u003e outside Stability AI’s control\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAutomated vulnerability scanning\u003c/strong\u003e or brute-force attacks that degrade service availability\u003c/li\u003e\n\u003cli\u003eAttacks targeting or exploiting \u003cstrong\u003eopen source model weights or checkpoints\u003c/strong\u003e, including inference behavior or re-hosting vulnerabilities outside of deployed production services\u003c/li\u003e\n\u003cli\u003eUse of \u003cstrong\u003estolen or leaked credentials\u003c/strong\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eImpersonation\u003c/strong\u003e on third-party platforms\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eGeneral best-practice or informational findings\u003c/strong\u003e that do not pose a meaningful threat to security or privacy\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eScope Compliance\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eOnly systems and assets explicitly listed as \u003cstrong\u003ein-scope\u003c/strong\u003e are authorized for testing.\u003c/li\u003e\n\u003cli\u003eInteract only with \u003cstrong\u003eaccounts and assets you own\u003c/strong\u003e or are explicitly permitted to test.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch1\u003eModel-Related Reports\u003c/h1\u003e\n\n\u003ch2\u003eModel Behavior Is Not a Security Bug\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eModel safety issues are not typically isolated or fixable software bugs.\u003c/li\u003e\n\u003cli\u003eThese issues often require broader research efforts and do not fit within the traditional framework of a bug bounty program.\u003c/li\u003e\n\u003cli\u003eTherefore, \u003cstrong\u003emodel behavior issues are not eligible\u003c/strong\u003e for rewards through this program.\u003c/li\u003e\n\u003cli\u003ePlease report them through the \u003cstrong\u003eappropriate feedback channels\u003c/strong\u003e, not the bug bounty process.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut-of-Scope Model Issues\u003c/h2\u003e\n\n\u003cp\u003eThe following categories are \u003cstrong\u003eexplicitly out of scope\u003c/strong\u003e and will not be eligible for bounty rewards:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003ePrompt injection or jailbreak techniques\u003c/strong\u003e (e.g., DAN-style prompts)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eOffensive or inappropriate model responses\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eInstructions resulting in harmful, unethical, or malicious content generation\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eModel hallucinations\u003c/strong\u003e (e.g., fabricated outputs, code, or secret information)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYou are expected, as always, to comply with all applicable laws.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the\u003c/em\u003e \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" title=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e\u003cem\u003eBugcrowd Support Portal\u003c/em\u003e\u003c/a\u003e \u003cem\u003ebefore going any further.\u003c/em\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"0bc4ee2e-ae20-4a34-a5f3-532aa3bf351c","name":"In Scope","targets":[{"id":"1b992367-adf0-41d1-80a8-1eb58d55df70","uri":"","name":"Stability.AI Infrastructure (https://*.stability.ai)","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"53e950c7-276c-4346-acfa-50fdf813414d","sortOrder":0},"sortOrder":0,"tags":[{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"1b992367-adf0-41d1-80a8-1eb58d55df70"},{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"1b992367-adf0-41d1-80a8-1eb58d55df70"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"1b992367-adf0-41d1-80a8-1eb58d55df70"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"1b992367-adf0-41d1-80a8-1eb58d55df70"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"1b992367-adf0-41d1-80a8-1eb58d55df70"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"1b992367-adf0-41d1-80a8-1eb58d55df70"}],"recentChangeFlags":null},{"id":"a4ab817f-975e-4d58-ae7d-13e80dcf425e","uri":"https://api.stability.ai/","name":"Stability Platform API","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"53a8c706-d3e0-4c37-b183-48c6a956cae8","sortOrder":1},"sortOrder":1,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"a4ab817f-975e-4d58-ae7d-13e80dcf425e"}],"recentChangeFlags":null},{"id":"70dce718-288d-45a1-81f7-ed23917f2866","uri":"https://dreamstudio.stability.ai/","name":"Dreamstudio Web Application","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d07943ac-d7cd-4357-b785-7ee2fd0d45c4","sortOrder":2},"sortOrder":2,"tags":[{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"70dce718-288d-45a1-81f7-ed23917f2866"},{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"70dce718-288d-45a1-81f7-ed23917f2866"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"70dce718-288d-45a1-81f7-ed23917f2866"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"70dce718-288d-45a1-81f7-ed23917f2866"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"70dce718-288d-45a1-81f7-ed23917f2866"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"70dce718-288d-45a1-81f7-ed23917f2866"}],"recentChangeFlags":null},{"id":"b7a9c031-5c02-4ac8-9fb5-30c6ee8f7f30","uri":"https://dreamstudio-api.stability.ai/","name":"Dreamstudio API","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b95dbbc1-a8e0-4a1a-886e-a73f43d7af8e","sortOrder":3},"sortOrder":3,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"b7a9c031-5c02-4ac8-9fb5-30c6ee8f7f30"}],"recentChangeFlags":null},{"id":"2d5dbb6e-ca74-478f-918a-1b7645e626e6","uri":"https://*.stableaudio.com/","name":"Stable Audio","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e9217de9-d9c8-495f-a320-fa4a1e3c8a8a","sortOrder":4},"sortOrder":4,"tags":[{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"2d5dbb6e-ca74-478f-918a-1b7645e626e6"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003cul\u003e\n\u003cli\u003e\u003cp\u003eStability.ai: Wildcard domain includes all public-facing services and subdomains operated by Stability AI, covering interfaces, APIs, model endpoints, and documentation platforms. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDreamstudio:  This application is Stability AI’s official user interface for interacting with our generative AI models, primarily Stable Diffusion. It allows users to generate and edit images through a graphical frontend backed by our production API.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eStable Audio: This application enables users to create original, high-quality music and sound effects from text prompts or audio input using the stable audio generative AI model.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003ehttps://api.stability.ai/  API: The https://api.stability.ai endpoint is the primary production API for accessing Stability AI’s suite of generative models, including text-to-image, image-to-image, and audio. It supports authenticated access via API keys, and serves as the backend for partner integrations.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"f702e8dd-2c84-4a41-bbbe-1754c14dc835","code":"stability-ai-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"91379258-5602-4530-9a63-7e0731377730","startsAt":"2025-05-13T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/7aca/8b36/c432bf11/c61c8a743a5c4adb3dc271a46e204617_stability_ai_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-05-13T18:00:03.182Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/stability-ai-vdp-pro","changelogs":"/engagements/stability-ai-vdp-pro/changelog","submissions":null,"announcements":"/engagements/stability-ai-vdp-pro/announcements","hallOfFame":"/engagements/stability-ai-vdp-pro/hall_of_fames","crowdstream":"/engagements/stability-ai-vdp-pro/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/stability-ai-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=stability-ai-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/stability-ai-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/stability-ai-vdp-pro/changelog","publishedAt":"2025-05-13T18:38:00.675Z","engagementChangelogUrl":"/engagements/stability-ai-vdp-pro/changelog/5bb417be-b5b1-4d4c-88de-e791ed4c4138","createUserFeedbacksUrl":"/engagements/stability-ai-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/stability-ai-vdp-pro/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}