You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Found a security vulnerability in a Hack Club program? We want to hear about it!
Report it through our bug bounty platform. All reports are handled there, do not open public GitHub issues for security vulnerabilities or reach out to individual maintainers directly.
Our bug bounty team validates whether it's a legitimate vulnerability
The team works on a fix
Once resolved, a GitHub Security Advisory is published on the affected repo with a link back to the full Aegis disclosure
Scope
All Hack Club programs are in scope. If you're unsure whether a vulnerability is in scope, submit it and we will make sure it gets to the right place.
Out of Scope
The following are generally considered out of scope:
Scraping public Slack information or account enumeration
Brute force attacks
Clickjacking without significant impact
Automated scanner outputs without real-world impact
Social engineering or phishing attacks
Self-exploitation requiring user interaction
Denial of Service causing resource exhaustion
Exploits related to Slack or other third-party services outside our control
AI Policy
Submissions that rely solely on AI with no original researcher input, testing, or validation will be rejected. AI should support your research, not replace it.
Contact
If you have any questions about our security policy or the reporting process, please reach out to us through email at security@hackclub.com or through the Slack. We take all reports seriously and will respond as quickly as possible. Thank you for helping us keep Hack Club safe!