Bug Bounty

Publicly disclosed reports from bug bounty and vulnerability disclosure programs (HackerOne, YesWeHack, Immunefi). Data is maintained in data/bounties.yaml.

PlatformProgramTitleSeverityBountyReportDate
Kuaishou SRCKling AI (可灵AI) 灵动画布Canvas project allows forcibly adding arbitrary users as collaborators without consentLow—Report2026-08-07
Kuaishou SRCKling AI (可灵AI) Developer ConsoleInternal /dev/kconf-editor tool exposed to any logged-in user, leaking internal KConf write interfaceLow—Report2026-08-07
Kuaishou SRCKling AI (可灵AI) Claw LoginClaw Login device-authorization flaw (no consent issuance + unauthenticated retrieval) enables one-click credential theftHigh—Report2026-08-06
JD SRCJD Cloud LingJing AI (京东云灵境AI)executeByApiId billing-logic vulnerability (race condition + missing quantity validation + balance-check bypass)Medium—Report2026-07-27