Security

Report a NativePath security issue

If you believe you found a vulnerability, report it privately with clear reproduction steps and minimal impact. Good-faith research helps keep learners, admins, and customers safe.

In scope

  • Authentication and sessions
  • Admin authorization
  • Public and authenticated APIs
  • Feedback, profile and public pages
  • CourseOps and ArticleOps rendering
  • AI routes and solution leakage prevention
  • Promo and billing integrity
  • Mobile API

Out of scope

  • Denial-of-service or high-volume load testing
  • Social engineering or phishing
  • Spam, SMS or email flooding
  • Destructive testing outside assigned test data
  • Third-party systems outside NativePath-owned configuration
Report template
Title: Severity: Affected URL/route: Account used: Environment: Steps to reproduce: Impact: Evidence: Suggested fix: Data accessed:

Do not include secrets, session cookies, or unrelated personal data. If private data is exposed accidentally, stop testing and include only the minimum evidence needed to prove impact.

NativePath does not promise a bounty, SLA, or authorization for destructive testing. Reports must be private, good-faith, and limited to the minimum reproduction needed.