Appwrite · Vulnerability Disclosure

Appwrite Vulnerability Disclosure

Vulnerability disclosure

Appwrite runs a coordinated vulnerability disclosure program on Hackerone.

ApplicationBackendMobileOpen SourceDatabaseStorageServerlessAuthenticationHostingAgents
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-12'
method: searched
source: >-
  https://github.com/appwrite/appwrite/blob/main/SECURITY.md (fetched verbatim 2026-09-12),
  https://appwrite.io/docs/advanced/security and
  https://appwrite.io/docs/advanced/security/penetration-tests.
provider: Appwrite
providerId: appwrite
program_published: true
program_type: coordinated disclosure
bug_bounty: false
bug_bounty_note: >-
  No HackerOne, Bugcrowd or Intigriti program and no published bounty table. Appwrite runs a
  coordinated-disclosure process with a private reporting channel, not a paid bounty.
security_txt:
  served: false
  note: >-
    No /.well-known/security.txt on appwrite.io, www.appwrite.io, cloud.appwrite.io,
    fra.cloud.appwrite.io or mcp.appwrite.io — all returned 404 on 2026-09-12. The policy exists; it
    is just not discoverable at the RFC 9116 path. See well-known/appwrite-well-known.yml.
channels:
  - type: private-vulnerability-reporting
    url: https://github.com/appwrite/appwrite/security/advisories/new
    preferred: true
  - type: email
    contact: security@appwrite.io
policy_url: https://github.com/appwrite/appwrite/blob/main/SECURITY.md
policy_pointer_in_apis_yml: https://github.com/appwrite/appwrite/blob/main/SECURITY.md
public_reporting_prohibited: >-
  Appwrite explicitly asks reporters NOT to use public GitHub issues, discussions or pull requests.
report_contents_requested:
  - A description of the issue and why it is security-sensitive
  - Affected versions, tags or commit SHAs
  - Steps to reproduce, or a proof of concept
  - Impact (confidentiality, integrity, availability, or privilege)
  - Any suggested mitigations or fixes
process: >-
  Appwrite acknowledges the report, follows up with next steps, works on a fix if confirmed, and
  coordinates public disclosure with the reporter, asking for reasonable time before public
  discussion.
scope:
  covered: The Appwrite server in the appwrite/appwrite repository.
  other_projects: >-
    Issues in SDKs, Console or Cloud go to that project's own security policy where one exists, or to
    security@appwrite.io.
supported_versions: >-
  Security updates are published for the latest stable self-hosted release; support phases and
  long-term coverage follow https://appwrite.io/docs/apis/release-policy.
proactive_testing:
  penetration_tests: true
  detail: >-
    Periodic third-party penetration tests and vulnerability assessments, with an internal and
    external information-security risk-management process and a risk treatment plan.
  docs: https://appwrite.io/docs/advanced/security/penetration-tests
advisories: https://github.com/appwrite/appwrite/security/advisories
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/appwrite-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.