Bug Bounty
Publicly disclosed reports from bug bounty and vulnerability disclosure programs (HackerOne, YesWeHack, Immunefi). Data is maintained in data/bounties.yaml.
| Platform | Program | Title | Severity | Bounty | Report | Date |
|---|---|---|---|---|---|---|
| Kuaishou SRC | Kling AI (可灵AI) 灵动画布 | Canvas project allows forcibly adding arbitrary users as collaborators without consent | Low | — | Report | 2026-08-07 |
| Kuaishou SRC | Kling AI (可灵AI) Developer Console | Internal /dev/kconf-editor tool exposed to any logged-in user, leaking internal KConf write interface | Low | — | Report | 2026-08-07 |
| Kuaishou SRC | Kling AI (可灵AI) Claw Login | Claw Login device-authorization flaw (no consent issuance + unauthenticated retrieval) enables one-click credential theft | High | — | Report | 2026-08-06 |
| JD SRC | JD Cloud LingJing AI (京东云灵境AI) | executeByApiId billing-logic vulnerability (race condition + missing quantity validation + balance-check bypass) | Medium | — | Report | 2026-07-27 |