In scope
- Authentication and sessions
- Admin authorization
- Public and authenticated APIs
- Feedback, profile and public pages
- CourseOps and ArticleOps rendering
- AI routes and solution leakage prevention
- Promo and billing integrity
- Mobile API
If you believe you found a vulnerability, report it privately with clear reproduction steps and minimal impact. Good-faith research helps keep learners, admins, and customers safe.
Do not include secrets, session cookies, or unrelated personal data. If private data is exposed accidentally, stop testing and include only the minimum evidence needed to prove impact.
NativePath does not promise a bounty, SLA, or authorization for destructive testing. Reports must be private, good-faith, and limited to the minimum reproduction needed.