If you discover a security vulnerability in this project, please report it responsibly.
Do NOT open a public GitHub issue. Instead, email the maintainer directly at the address listed in the GitHub profile.
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof of concept
- Affected version(s)
- Suggested fix (optional)
You will receive a response within 72 hours. If the vulnerability is confirmed, a fix will be released and you will be credited (unless you prefer otherwise).
This policy applies only to vulnerabilities in the bugbounty-ctf project
itself — not to targets you test using this toolkit.
This toolkit is for authorized security testing only. Always obtain explicit permission before testing any target. Unauthorized testing is illegal.