If you discover a security vulnerability in AppSec Atlas (including the website infrastructure, any lab components, or tooling), please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Email: security@appsecatlas.com
Include:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Your recommended fix (optional but appreciated)
| Phase | Timeline |
|---|---|
| Acknowledgement | Within 48 hours |
| Initial assessment | Within 5 business days |
| Fix or mitigation | Within 30 days (critical: 7 days) |
| Public disclosure | After fix is deployed |
In scope:
- The AppSec Atlas website (appsecatlas.com)
- CI/CD pipeline misconfigurations
- Lab Docker images with unintended real vulnerabilities
Out of scope:
- Intentional vulnerabilities in lab exercises (they are designed to be vulnerable for educational purposes)
- Third-party services we use (report directly to them)
Security researchers who responsibly disclose valid vulnerabilities will be credited in our Security Hall of Fame (with their permission).
Thank you for helping keep AppSec Atlas safe! 🔐