{"id":"a11269ee-8680-42ef-b93e-92d82d5ca555","engagementId":"4f57c697-ad9a-423f-8e30-068fb7351258","data":{"brief":{"id":"6ad72c30-cbeb-4136-b5bc-0d751c073e0c","name":"YNAB","tagline":"Download YNAB to get good with money and never worry about it again.","description":"\u003cp\u003eAt YNAB, we take security seriously. We work hard to protect our users and their data, staying ahead of emerging threats by collaborating with security researchers. If you discover a security vulnerability or think we’ve made a mistake, please report it to us immediately. Good luck and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"6bf30795-7930-4c2b-bb79-d2c4f15f7740","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of YNAB not listed in the targets section is out of scope. This includes any/all subdomains not listed above.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOur Philosophy\u003c/h2\u003e\n\n\u003cp\u003eWe’re on your side - we both want vulnerabilities to be found by you before malicious actors exploit them. However, we expect researchers to operate responsibly and in good faith. Please review the rules below before carrying out any type of testing:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eTest only your own accounts - do not access, alter, or interact with real user data.\u003c/li\u003e\n\u003cli\u003eFollow responsible disclosure practices - report issues promptly and keep them confidential. \u003ca href=\"https://bugcrowd.com/resources/standard-disclosure-terms\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd's standard disclosure terms\u003c/a\u003e always apply.\u003c/li\u003e\n\u003cli\u003eDo not perform denial-of-service (DoS/DDoS) attacks - these disrupt our systems and users.\u003c/li\u003e\n\u003cli\u003eDo not attempt social engineering, phishing, or physical security attacks - this includes trying to break into our offices or manipulate employees.\u003c/li\u003e\n\u003cli\u003eDo not use aggressive automated scanning tools - they generate excessive traffic and may result in account lockouts.\u003c/li\u003e\n\u003cli\u003eDo not waste time with non-security-related issues - we are only interested in actual security risks, not general application bugs. This includes broken links on our web app. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess/Credentials\u003c/h2\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e. If you need multiple accounts, use username+2@bugcrowdninja.com.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eUser enumeration (during signup, login, or password reset).\u003c/li\u003e\n\u003cli\u003eEmail spoofing (SPF/DKIM settings exist but DMARC may be in testing).\u003c/li\u003e\n\u003cli\u003eDenial of Service (DoS) attacks, unless it’s a rare case that crashes our server (e.g., malformed JSON input).\u003c/li\u003e\n\u003cli\u003eSelf-XSS (unless exploitable via the UI).\u003c/li\u003e\n\u003cli\u003eBugs affecting outdated browsers (only the latest versions of Chrome, Firefox, Safari, and Edge are supported).\u003c/li\u003e\n\u003cli\u003eCSRF attacks on non-authenticated pages (including login/logout forms).\u003c/li\u003e\n\u003cli\u003eTLS/SSL issues (unless extremely severe).\u003c/li\u003e\n\u003cli\u003eClick-jacking.\u003c/li\u003e\n\u003cli\u003eSubdomain takeovers (on Heroku-hosted subdomains - we have safeguards in place).\u003c/li\u003e\n\u003cli\u003eBroken link hijacking (unless we are actively loading resources from an expired domain).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"4846989b-b71f-4089-b171-cc66f3a84d08","name":"In Scope","targets":[{"id":"692d8b99-ac85-4358-990b-17cb4a36b2cd","uri":"","name":"staging-app.bany.dev","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6ce9f263-57e2-4710-b65c-b8ab8baca115","sortOrder":0},"sortOrder":0,"tags":[{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"692d8b99-ac85-4358-990b-17cb4a36b2cd"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"692d8b99-ac85-4358-990b-17cb4a36b2cd"},{"id":"b0471577-6c74-4b1b-89aa-82ef39c444b7","name":"Heroku","targetId":"692d8b99-ac85-4358-990b-17cb4a36b2cd"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"692d8b99-ac85-4358-990b-17cb4a36b2cd"},{"id":"dd477d24-b394-460d-aaf7-9bd213555968","name":"Ruby","targetId":"692d8b99-ac85-4358-990b-17cb4a36b2cd"}],"recentChangeFlags":null},{"id":"2bb11c3a-bb06-48f3-97a6-b703cd984871","uri":"https://staging-api.bany.dev/","name":"staging-api.bany.dev","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"70ab677d-f8c7-40f9-9c5c-a4472d4229cc","sortOrder":1},"sortOrder":1,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"2bb11c3a-bb06-48f3-97a6-b703cd984871"}],"recentChangeFlags":null},{"id":"ed19c6f9-cddc-4933-877f-e193b36b142b","uri":"https://www.ynab.com/","name":"www.ynab.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f380b0ca-7155-423c-8e8f-6beebbb8c961","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"e0635f91-54f3-40dd-afaf-63f862ee3c41","p1MaxCents":300000,"p1MinCents":300000,"p2MaxCents":135000,"p2MinCents":135000,"p3MaxCents":80000,"p3MinCents":80000,"p4MaxCents":15000,"p4MinCents":15000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003e✅ YNAB Web App \u0026amp; API (Staging)\u003cbr\u003e\nOur single-page application and private API endpoint are primary targets. You’ll see API calls when interacting with the app in your browser.\u003cbr\u003e\n✅ Public API (Staging)\u003cbr\u003e\nThe public API documentation references api.ynab.com, but please test using the URL \u003ca href=\"https://staging-api.bany.dev/v1\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://staging-api.bany.dev/v1\u003c/a\u003e and then select the production server \u003ca href=\"https://api.ynab.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://api.ynab.com\u003c/a\u003e.\u003cbr\u003e\n✅ YNAB Marketing Site (www.ynab.com)\u003cbr\u003e\nThis is a WebFlow site and is low risk, as it stores minimal data. Findings are still appreciated.\u003cbr\u003e\n✅ 2FA Sign-In\u003cbr\u003e\nAny security vulnerabilities related to two-factor authentication are in scope. Documentation can be found on our \u003ca href=\"https://support.ynab.com/en_us/how-to-protect-your-account-with-two-step-verification-rkKHuLlRc#troubleshoot\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSupport site\u003c/a\u003e. \u003cbr\u003e\n✅ Any YNAB-owned host (*.ynab.com)\u003cbr\u003e\nExcept for explicitly out-of-scope targets (listed below).\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003eAny other host verified to be owned by YNAB, like *.ynab.com, is in scope except for those noted above.\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch2\u003ePlatform \u0026amp; Technology Stack\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eClient-Side:\u003c/strong\u003e\u003cbr\u003e\nEmber.js Single-Page Application\u003cbr\u003e\nLatest versions of Chrome, Safari, Edge, and Firefox supported\u003cbr\u003e\n\u003cstrong\u003eServer-Side:\u003c/strong\u003e\u003cbr\u003e\nRuby on Rails 7.x (Running on Heroku)\u003cbr\u003e\nRuby 3.x, Puma 6.x\u003cbr\u003e\nCrunchyBridge Postgres\u003cbr\u003e\nCloudFront CDN\u003cbr\u003e\n\u003cstrong\u003eMarketing Site:\u003c/strong\u003e\u003cbr\u003e\nWebFlow\u003c/p\u003e","rewardRangeData":{"1":{"min":3000,"max":3000},"2":{"min":1350,"max":1350},"3":{"min":800,"max":800},"4":{"min":150,"max":150},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"bedc03fa-6e92-476d-8eb9-e8c8209266cd","name":"Out of Scope ","targets":[{"id":"7b96f02d-344d-414d-8e3b-c473cb4ea782","uri":null,"name":"https://app.ynab.com/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"587c8d41-ad52-47b5-b859-8b9bb0392a12","sortOrder":0},"sortOrder":0,"tags":[{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"7b96f02d-344d-414d-8e3b-c473cb4ea782"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"7b96f02d-344d-414d-8e3b-c473cb4ea782"}],"recentChangeFlags":null},{"id":"488768d5-a057-43f7-84c2-30ee127a5984","uri":null,"name":"Any previous version of the desktop apps: YNAB 4, YNAB 3, YNAB Pro, YNAB Basic (Spreadsheet)","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"02c5c87b-b6e5-4b31-b891-b7ddda8daaf6","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"1442f567-69d6-4211-b83e-3e7712169f5e","uri":null,"name":"https://support.ynab.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"33cbb649-12d2-4918-b860-281e35b49c8b","sortOrder":2},"sortOrder":2,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"1442f567-69d6-4211-b83e-3e7712169f5e"}],"recentChangeFlags":null},{"id":"d3fae3e9-0e22-4dc4-9ac4-f7d911a09c74","uri":null,"name":"https://develop-app.ynab.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6a1ad462-7ccd-4c77-b8bc-7d779d8f9880","sortOrder":3},"sortOrder":3,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d3fae3e9-0e22-4dc4-9ac4-f7d911a09c74"}],"recentChangeFlags":null},{"id":"4cc3f5ce-add6-4261-8f6c-b780565e193a","uri":"","name":"https://learn.ynab.com/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ef8a1ea1-1361-44c1-93a0-1c26b0cc3232","sortOrder":4},"sortOrder":4,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"4cc3f5ce-add6-4261-8f6c-b780565e193a"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003e🚫 Production environments: https://app.ynab.com/ (Live production app). \u003cstrong\u003eOur customers’ real data is off-limits!\u003c/strong\u003e\u003cbr\u003e\n🚫 Older desktop applications: YNAB 4, YNAB 3, YNAB Pro, YNAB Basic (Spreadsheet)\u003cbr\u003e\n🚫 Support Site: https://support.ynab.com/ (Hosted by a third party)\u003cbr\u003e\n🚫 YNAB Learn: https://learn.ynab.com/ (Hosted by a third party)\u003cbr\u003e\n🚫 Internal Testing \u0026amp; Development Sites: https://develop-app.ynab.com\u003cbr\u003e\n🚫 Any customer accounts or real user data\u003cbr\u003e\n🚫 Testing beyond explicitly in-scope targets\u003cbr\u003e\n🚫 YNAB Mobile Applications (iOS and Android)\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"4f57c697-ad9a-423f-8e30-068fb7351258","code":"ynab","state":"in_progress","endsAt":null,"bountyId":"ecfe3883-8d4d-4fe4-8971-a7daf88363b1","startsAt":"2022-10-19T17:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Finance","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/74db/98a2/d8d154a4/858155d20c942a7a64eb370961433813_Group_288__1_.png","logoBackgroundColor":"#3B5EDA","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2022-10-19T17:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/ynab","changelogs":"/engagements/ynab/changelog","submissions":null,"announcements":"/engagements/ynab/announcements","hallOfFame":"/engagements/ynab/hall_of_fames","crowdstream":"/engagements/ynab/crowdstream"},"announcementsCount":7,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/ynab/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=ynab\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/ynab/engagement_subscribers","engagementChangelogsUrl":"/engagements/ynab/changelog","publishedAt":"2026-03-05T21:41:59.525Z","engagementChangelogUrl":"/engagements/ynab/changelog/a11269ee-8680-42ef-b93e-92d82d5ca555","createUserFeedbacksUrl":"/engagements/ynab/feedbacks","engagementCrowdstreamUrl":"/engagements/ynab/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}