Linear
Linear Vulnerability Disclosure · Self-hosted / private program Active
Scope
At a glance
- Platform: Self-hosted, report by email
- Rewards: Yes. Amounts informed by CVSS 4.0 base score, generally 4.0 or higher to qualify, adjusted for the affected component and real-world impact
- Public disclosure: Not before reporting, and only after they have had adequate time to fix
- Report to: security@linear.app
In scope
linear.appclient-api.linear.appsync.linear.appuploads.linear.appintake.linear.appapi.linear.app(public API)mcp.linear.app(MCP server)- Linear-built integrations
- Desktop applications for macOS and Windows
Out of scope
- Automated scanning of any kind
- Social engineering, in particular of Linear employees
- Denial of service of any kind
- Anything requiring physical access
- Theoretical issues with no proof of exploitability
- Man-in-the-middle attacks
- HTTP and DNS configuration findings
Reporting
Email security@linear.app with a summary, steps to reproduce, the
environment, and proof-of-concept code where you have it.