Reporting a vulnerability
How to tell us about a security issue.
We would rather hear about it.
How to report
Use the security contact at lenshub.ai/security, which also carries the full policy.
Useful reports include steps to reproduce, the affected component or endpoint, and what an attacker could actually achieve.
What to expect
Acknowledgement within 24 hours, and a triage decision within 72.
We do not run a paid bounty programme. We do credit researchers publicly on request.
Good-faith research
Test against your own instance. Do not access other people's data, degrade the service, or disclose publicly before we have had a chance to fix the issue. Research conducted along those lines is welcome and we will not pursue it.
Self-hosted instances
If you self-host, your instance is yours to secure — but a vulnerability in LensHub itself affects everyone running it, so please report those the same way.