API Dash · Vulnerability Disclosure

Api Dash Vulnerability Disclosure

Vulnerability disclosure

API Dash runs a coordinated vulnerability disclosure program on Hackerone.

API ClientOpen-SourceFlutterDesktopMobile
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-02'
method: searched
probe: true
source: https://github.com/foss42/apidash/blob/main/SECURITY.md
note: >-
  0-working/probe-security-programs.py reported vdp=none on 2026-09-02, and that is a true result
  for the paths it checks: neither host serves /.well-known/security.txt, and apidash.dev is an SPA
  whose edge returns the same HTML shell for /security and /responsible-disclosure. The program is
  real nonetheless — it lives in the repository rather than on the website, which is the normal
  shape for an open-source project. Recorded searched, with the probe result kept alongside it so
  the negative is not lost.
policy:
- https://github.com/foss42/apidash/blob/main/SECURITY.md
intake:
- kind: github-security-advisory
  url: https://github.com/foss42/apidash/security/advisories/new
  preferred: true
  note: SECURITY.md directs researchers to open a DRAFT security advisory for discussion and collaboration on the fix, and explicitly asks that vulnerabilities NOT be reported through public GitHub issues.
- kind: email
  value: ankit[at]apidash.dev
  source: https://github.com/foss42/apidash/blob/main/doc/security/README.md
  note: Published de-obfuscated nowhere; recorded exactly as the provider writes it.
scope:
  covers: API Dash application and the Dart/Flutter packages in the API Dash repository
  source: SECURITY.md ("management of vulnerabilities for API Dash project & the Dart/Flutter packages in the repository")
requested_report_contents:
- Type of issue (buffer overflow, poisoned dependency, cross-site scripting, etc.)
- Full paths of source files related to the issue
- Location of the affected source code (tag/branch/commit or direct URL)
- Special configuration required to reproduce
- Step-by-step reproduction instructions
- Proof-of-concept or exploit code, if possible
- Impact, including how an attacker might exploit it
supporting_documentation:
- {title: Threat Model, url: 'https://github.com/foss42/apidash/blob/main/doc/security/THREAT_MODEL.md'}
- {title: Incident Response Plan, url: 'https://github.com/foss42/apidash/blob/main/doc/security/INCIDENT_RESPONSE_PLAN.md'}
- {title: Security documentation index, url: 'https://github.com/foss42/apidash/blob/main/doc/security/README.md'}
- {title: SBOM, url: 'https://github.com/foss42/apidash/blob/main/doc/security/sbom.json', note: 'A published software bill of materials — rare for a project this size and worth naming.'}
bug_bounty: null
bug_bounty_note: No HackerOne, Bugcrowd or Intigriti program was found. Disclosure is unpaid and coordinated through GitHub.
response_sla:
  stated: false
  note: doc/security/README.md refers to "SLAs based on severity - see the IRP" but SECURITY.md itself states no numeric response time.
evidence:
- {source: 'https://github.com/foss42/apidash/blob/main/SECURITY.md', kind: security-policy, http_status: 429, note: 'GitHub rate-limited our crawler on this one URL; the raw.githubusercontent.com copy fetched 200 and its full text is quoted above. Not dead.'}
- {source: 'https://raw.githubusercontent.com/foss42/apidash/main/SECURITY.md', kind: security-policy, http_status: 200}
- {source: 'https://raw.githubusercontent.com/foss42/apidash/main/doc/security/README.md', kind: security-docs, http_status: 200}
- {source: 'https://apidash.dev/.well-known/security.txt', kind: negative-probe, http_status: 200, verdict: 'soft-404 - SPA shell, 42967 bytes of HTML, identical to a random control path'}
- {source: 'https://api.apidash.dev/.well-known/security.txt', kind: negative-probe, http_status: 404}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/api-dash-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.