PentestingHere
Log in Join

Linear

Linear Vulnerability Disclosure · Self-hosted / private program Active

Official page

Scope

At a glance

  • Platform: Self-hosted, report by email
  • Rewards: Yes. Amounts informed by CVSS 4.0 base score, generally 4.0 or higher to qualify, adjusted for the affected component and real-world impact
  • Public disclosure: Not before reporting, and only after they have had adequate time to fix
  • Report to: security@linear.app

In scope

  • linear.app
  • client-api.linear.app
  • sync.linear.app
  • uploads.linear.app
  • intake.linear.app
  • api.linear.app (public API)
  • mcp.linear.app (MCP server)
  • Linear-built integrations
  • Desktop applications for macOS and Windows

Out of scope

  • Automated scanning of any kind
  • Social engineering, in particular of Linear employees
  • Denial of service of any kind
  • Anything requiring physical access
  • Theoretical issues with no proof of exploitability
  • Man-in-the-middle attacks
  • HTTP and DNS configuration findings

Reporting

Email security@linear.app with a summary, steps to reproduce, the environment, and proof-of-concept code where you have it.

Is it worth your time?

Read the community feedback

1 review rating communication, triage, payouts and whether it suits beginners.

Open feedback