— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Notion Labs, Inc..
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"allows_bounty_splitting": true,
"average_time_to_bounty_awarded": 669,
"average_time_to_first_program_response": 8,
"average_time_to_report_resolved": 1340,
"handle": "notion",
"id": 0,
"managed_program": true,
"name": "Notion Labs, Inc.",
"offers_bounties": true,
"offers_swag": false,
"response_efficiency_percentage": 93,
"submission_state": "open",
"url": "https://hackerone.com/notion",
"website": "http://www.notion.so",
"targets": {
"in_scope": [
{
"asset_identifier": "Github Repositories or other public artifacts owned by makenotion",
"asset_type": "OTHER",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": "low",
"max_severity": "critical"
},
{
"asset_identifier": "Notion AI",
"asset_type": "AI_MODEL",
"availability_requirement": "medium",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "We are particularly interested in the ability to access data the user lacks permission to view. Prompt engineering for inappropriate AI responses is out of scope. The usage of obfuscated or invisible characters to alter AI responses is in scope if security impact can be demonstrated.",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "Notion Authentication",
"asset_type": "OTHER",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": null,
"integrity_requirement": "not_defined",
"max_severity": "critical"
},
{
"asset_identifier": "Notion Desktop App",
"asset_type": "DOWNLOADABLE_EXECUTABLES",
"availability_requirement": "low",
"confidentiality_requirement": "medium",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Any desktop app available for download at www.notion.so/desktop\n\nWe only reward for the most recent version of the app.",
"integrity_requirement": "medium",
"max_severity": "critical"
},
{
"asset_identifier": "Notion Frontend",
"asset_type": "OTHER",
"availability_requirement": "low",
"confidentiality_requirement": "medium",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Includes any resources served to or affects a user from notion.so/ or our marketing site on notion.so.",
"integrity_requirement": "medium",
"max_severity": "critical"
},
{
"asset_identifier": "Notion Integrations",
"asset_type": "OTHER",
"availability_requirement": "medium",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "We are most interested in any CSRF in third-party integrations.",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "Privilege Escalation",
"asset_type": "OTHER",
"availability_requirement": "medium",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "We are particularly interested in the ability to access pages a given user should lack the ability to access. \n\nAdditionally, if a page is available through “Anyone with a link at…” (permission grant), we are interested in cases where another user could access that page without explicitly receiving the link.",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "Product API",
"asset_type": "OTHER",
"availability_requirement": "medium",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Includes resources at notion.so/api/v3.\n\nAttacks we are most interested in receiving reports about include: injection attacks, remote code execution, server-side request forgery, IDOR, and privilege escalation. This list is not exhaustive; please submit anything related to the API here.",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "Public API",
"asset_type": "OTHER",
"availability_requirement": "medium",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Includes resources at [api.notion.com](https://api.notion.com/).\n\nWe are particularly interested in the ability to escalate your privileges beyond the scope of our API tokens.",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "calendar.notion.so",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "medium",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": null,
"integrity_requirement": "medium",
"max_severity": "critical"
},
{
"asset_identifier": "mail.notion.so",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": null,
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "notion.id",
"asset_type": "GOOGLE_PLAY_APP_ID",
"availability_requirement": "low",
"confidentiality_requirement": "medium",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Includes the Android app available for download at https://play.google.com/store/apps/details?id=notion.id. We only reward for the most recent version of the app.",
"integrity_requirement": "medium",
"max_severity": "critical"
}
],
"out_of_scope": []
}
}Github Repositories or other publi…artifacts owned by makenotion· criticalNotion AI· criticalNotion Authentication· criticalNotion Desktop App· criticalNotion Frontend· criticalNotion Integrations· criticalPrivilege Escalation· criticalProduct API· criticalPublic API· critical— none listed —