Academia · Vulnerability Disclosure

Academia Vulnerability Disclosure

Vulnerability disclosure

Academia runs a coordinated vulnerability disclosure program on Bugcrowd. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyAcademic Researchresearch-papersScholarly PublishingHigher EducationOpen Accessacademic-social-networkPreprintsresearch-discovery
Program: Bugcrowd security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:security@academia.edu

Source

Vulnerability Disclosure

academia-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-06'
method: searched
probe: true
source: https://www.academia.edu/.well-known/security.txt
contact:
- mailto:security@academia.edu
policy:
- https://www.academia.edu/.well-known/security.txt
canonical: https://academia.edu/.well-known/security.txt
expires: '2026-09-05T13:16:09Z'
preferred_languages:
- en
bug_bounty:
  formal_public_program: false
  discretionary_bounties: true
  statement: >-
    "We do not operate a formal public bug bounty program. We may award discretionary bounties for
    high-quality reports." Bounties are considered case by case for reports that identify a previously
    unknown issue, demonstrate real security impact, and are responsibly disclosed.
  severity_taxonomy:
    name: Bugcrowd Vulnerability Rating Taxonomy (P1-P5)
    url: https://bugcrowd.com/vulnerability-rating-taxonomy
    note: >-
      Academia asks reporters to use the Bugcrowd VRT terminology and include a P1-P5 severity rating.
      This is a reference to the taxonomy only - there is no Bugcrowd-hosted program.
prioritized_classes:
- authentication bypass or account takeover
- data exposure or access control issues
- cross-site scripting (XSS) with working proof of concept
- privilege escalation
lower_priority_classes:
- best-practice recommendations without exploitability
- automated scan results without validation
- hypothetical or purely theoretical scenarios
report_expectations:
- confirmed vulnerability rather than a theoretical concern
- clear, reproducible steps
- demonstrated concrete impact
- minimal reproduction, proof-of-concept code, or a short screen recording
evidence:
- source: well-known/academia-security.txt
  kind: security.txt
  url: https://www.academia.edu/.well-known/security.txt
  http_status: 200
  content_type: text/plain; charset=utf-8
  fetched: '2026-08-06'
notes: >-
  The whole disclosure policy is published inline in the security.txt as comment blocks rather than at a
  separate Policy: URL, so the RFC 9116 file itself is the policy document. No Policy:, Encryption:,
  Acknowledgments: or Hiring: fields are present.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/academia-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.