Skip to content

Last updated 15 August 2026

Security

How to report a vulnerability in our tools or this website, and what happens after you do.

Reporting a vulnerability

If you have found a security issue in one of our tools or in this website, email hello@0xexploitlabs.org with enough detail to reproduce it. A proof of concept, affected versions and the impact you believe it has are the most useful things you can include.

Please do not open a public issue for anything exploitable until we have had a chance to fix it.

What we commit to

  • We acknowledge reports within 72 hours.
  • We give you an assessment and a rough timeline within 7 days.
  • We credit you in the release notes unless you would rather we did not.
  • We will not pursue legal action against good-faith research that follows this policy.

Scope

In scope: this website, and any repository under the 0xExploit-Labs GitHub organisation.

Out of scope: findings that require physical access, social engineering of our people, denial of service, and reports produced by an automated scanner with no demonstrated impact.

No bounty, yet

We do not currently run a paid bug bounty. We do read every report, we fix what is real, and we say thank you properly in public.