Security

Report a NativePath security issue

If you believe you found a vulnerability, report it privately with clear reproduction steps and minimal impact. We appreciate good-faith research that helps keep learners, admins and customers safe.

In scope

  • - Authentication and sessions
  • - Admin authorization
  • - Public and authenticated APIs
  • - Feedback, profile and public pages
  • - CourseOps and ArticleOps rendering
  • - AI routes and solution leakage prevention
  • - Promo, referral and XP reward integrity
  • - Mobile API

Out of scope

  • - Denial-of-service or high-volume load testing
  • - Social engineering or phishing
  • - Spam, SMS or email flooding
  • - Destructive testing outside assigned test data
  • - Third-party systems outside NativePath-owned configuration

Report template

Title:

Severity:

Affected URL/route:

Account used:

Environment:

Steps to reproduce:

Impact:

Evidence:

Suggested fix:

Data accessed:

Do not include secrets, session cookies or unrelated personal data. If private data is exposed accidentally, stop testing and include only the minimum evidence needed to prove impact.

NativePath does not promise a bounty, SLA or authorization for destructive testing. Reports must be private, good-faith and limited to the minimum reproduction needed.