{"id":"1a7caeff-79d1-4293-8c2f-8e290fe0d805","engagementId":"c9a46fca-8025-451c-a99d-e76dfc7f612a","data":{"brief":{"id":"5d28d067-8de7-425b-a6e5-844823fe507f","name":"Stake Vulnerability Disclosure Engagement","tagline":"Stake.com online Casino offers casino games such as slots, blackjack, roulette, and sports betting. It offers also video streams with live dealers.","description":"\u003cp\u003eNo technology is perfect and Stake believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our platform. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eFor all submissions, please ensure there is a viable security impact derived from it, regular bug submissions (i.e, with no real security impact) or submissions with minimal security impact due to the nature of the feature and/or product, will be reduced in severity and/or not triaged.\u003c/em\u003e\u003c/p\u003e","industryTagId":"ef2b9ee7-7f73-4978-9530-ad18bbf3f902","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Stake not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Stake, you can report it to this engagement.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eGraphQL services\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eCredentials\u003c/h3\u003e\n\n\u003cp\u003eAccounts on all publicly facing targets can be self-provisioned. Please sign up for an account using your @bugcrowdninja.com email address as they will be automatically approved and will allow for testing of all features without needing to make a payment. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"59057fde-0503-404b-a520-b6b1d018bd3f","name":"In Scope","targets":[{"id":"c08694de-8805-4ebb-8074-7a237a062c7c","uri":"https://stake.com/*","name":"https://stake.com/*","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"68203ed2-9183-495d-8fdd-2cb70d260d3b","sortOrder":0},"sortOrder":0,"tags":[{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"c08694de-8805-4ebb-8074-7a237a062c7c"},{"id":"4aeb1677-ac84-4afd-827e-054b363ca984","name":"GraphQL","targetId":"c08694de-8805-4ebb-8074-7a237a062c7c"},{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"c08694de-8805-4ebb-8074-7a237a062c7c"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"c08694de-8805-4ebb-8074-7a237a062c7c"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"c9a46fca-8025-451c-a99d-e76dfc7f612a","code":"stake-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"f1842e44-abc4-4a43-82ab-0a61601c0ba1","startsAt":"2026-02-05T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Entertainment","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/e126/e715/278f072c/9efab373662b2cb17f70c97e604dd603_Screenshot_2024-02-19_at_10.52.14_am.png","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-02-05T18:00:01.331Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/stake-vdp-pro","changelogs":"/engagements/stake-vdp-pro/changelog","submissions":null,"announcements":"/engagements/stake-vdp-pro/announcements","hallOfFame":"/engagements/stake-vdp-pro/hall_of_fames","crowdstream":"/engagements/stake-vdp-pro/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/stake-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=stake-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/stake-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/stake-vdp-pro/changelog","publishedAt":"2026-02-05T18:00:01.392Z","engagementChangelogUrl":"/engagements/stake-vdp-pro/changelog/1a7caeff-79d1-4293-8c2f-8e290fe0d805","createUserFeedbacksUrl":"/engagements/stake-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/stake-vdp-pro/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}