Appwrite · Vulnerability Disclosure
Appwrite Vulnerability Disclosure
Vulnerability disclosure
Appwrite runs a coordinated vulnerability disclosure program on Hackerone.
ApplicationBackendMobileOpen SourceDatabaseStorageServerlessAuthenticationHostingAgents
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-12'
method: searched
source: >-
https://github.com/appwrite/appwrite/blob/main/SECURITY.md (fetched verbatim 2026-09-12),
https://appwrite.io/docs/advanced/security and
https://appwrite.io/docs/advanced/security/penetration-tests.
provider: Appwrite
providerId: appwrite
program_published: true
program_type: coordinated disclosure
bug_bounty: false
bug_bounty_note: >-
No HackerOne, Bugcrowd or Intigriti program and no published bounty table. Appwrite runs a
coordinated-disclosure process with a private reporting channel, not a paid bounty.
security_txt:
served: false
note: >-
No /.well-known/security.txt on appwrite.io, www.appwrite.io, cloud.appwrite.io,
fra.cloud.appwrite.io or mcp.appwrite.io — all returned 404 on 2026-09-12. The policy exists; it
is just not discoverable at the RFC 9116 path. See well-known/appwrite-well-known.yml.
channels:
- type: private-vulnerability-reporting
url: https://github.com/appwrite/appwrite/security/advisories/new
preferred: true
- type: email
contact: security@appwrite.io
policy_url: https://github.com/appwrite/appwrite/blob/main/SECURITY.md
policy_pointer_in_apis_yml: https://github.com/appwrite/appwrite/blob/main/SECURITY.md
public_reporting_prohibited: >-
Appwrite explicitly asks reporters NOT to use public GitHub issues, discussions or pull requests.
report_contents_requested:
- A description of the issue and why it is security-sensitive
- Affected versions, tags or commit SHAs
- Steps to reproduce, or a proof of concept
- Impact (confidentiality, integrity, availability, or privilege)
- Any suggested mitigations or fixes
process: >-
Appwrite acknowledges the report, follows up with next steps, works on a fix if confirmed, and
coordinates public disclosure with the reporter, asking for reasonable time before public
discussion.
scope:
covered: The Appwrite server in the appwrite/appwrite repository.
other_projects: >-
Issues in SDKs, Console or Cloud go to that project's own security policy where one exists, or to
security@appwrite.io.
supported_versions: >-
Security updates are published for the latest stable self-hosted release; support phases and
long-term coverage follow https://appwrite.io/docs/apis/release-policy.
proactive_testing:
penetration_tests: true
detail: >-
Periodic third-party penetration tests and vulnerability assessments, with an internal and
external information-security risk-management process and a risk treatment plan.
docs: https://appwrite.io/docs/advanced/security/penetration-tests
advisories: https://github.com/appwrite/appwrite/security/advisories
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/appwrite-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.