Cylvern CTF is still a work in progress. Please bare with us for now.

Vulnerability
Disclosure Programme

We believe in working with the security community to protect our users. If you've found a vulnerability in Cylvern's infrastructure, we want to hear from you.

Safe Harbour

Cylvern Security will not pursue legal action against researchers who discover and report vulnerabilities in good faith in accordance with this policy. We consider security research conducted under this VDP as authorised and will not refer researchers to law enforcement. We ask only that you do not disrupt services, exfiltrate data, or target users.

In Scope

Asset Type Notes
cylsec.com Web Main marketing site
ctf.cylsec.com Web CTF platform — all user-facing endpoints
*.cylsec.com Subdomain Any subdomain actively serving content

Out of Scope

  • Social engineering or phishing attacks against Cylvern staff
  • Physical security attacks
  • Denial-of-service (DoS/DDoS) attacks
  • Vulnerabilities in third-party services not under our control
  • Intentional CTF challenge vulnerabilities (those are features, not bugs)
  • Automated scanner noise without proof of exploitability

Response Times

Severity Examples Acknowledgement Resolution Target
Critical RCE, auth bypass, mass data exfiltration 24 hours 7 days
High SSRF, SQLi, privilege escalation 48 hours 14 days
Medium Stored XSS, IDOR, sensitive info leak 5 days 30 days
Low / Info Missing headers, clickjacking, open redirect 7 days 60 days

Disclosure Process

1

Submit Report

Email security@cylsec.com with a clear title, steps to reproduce, proof-of-concept, and impact assessment.

2

Acknowledgement

We will acknowledge your report within the SLA window and assign a tracking reference.

3

Triage & Validation

Our team validates the vulnerability and assesses severity using CVSS 3.1.

4

Remediation

We patch or mitigate the vulnerability and verify the fix in staging and production.

5

Disclosure

We coordinate disclosure timing with you. We aim for 90 days from initial report to public disclosure.

Security Researchers

We recognise and thank the researchers who have responsibly disclosed vulnerabilities to us.

No submissions yet. Be the first to be listed here!

How to Report

Email

Send vulnerability reports to:

security@cylsec.com

Please include: vulnerability description, steps to reproduce, impact, affected asset, and any proof-of-concept.

Discord

For non-sensitive issues, you may also reach us on Discord:

discord.gg/gveJetDthV

Do not post vulnerability details publicly in Discord — use private messages to a moderator.