Autodesk PowerMill · Vulnerability Disclosure

Autodesk Powermill Vulnerability Disclosure

Vulnerability disclosure

Autodesk PowerMill runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

5-Axis MachiningCAMCNCMachiningManufacturingAerospaceAutomotiveToolpath Generation
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
https://hackerone.com/autodesk

Source

Vulnerability Disclosure

autodesk-powermill-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-06'
method: searched
probe: true
scope: >-
  Autodesk-wide. PowerMill is an Autodesk product (x-parent: autodesk) and does not run its own
  disclosure programme; Autodesk's programme explicitly covers "Desktop and mobile applications"
  and "any Autodesk-owned system, application, or service", which is what PowerMill is.
policy:
  - https://hackerone.com/autodesk
contact:
  - https://hackerone.com/autodesk
programme:
  platform: HackerOne
  handle: autodesk
  url: https://hackerone.com/autodesk
  launched_publicly: '2025-01-27'
  submission_state: open
  offers_bounties: false
  offers_swag: true
  offers_thanks: true
  researcher_count: 279
  resolved_report_count: 1215
  safe_harbor: true
  response_targets:
    first_response_business_days: 2
    time_to_triage_business_days: 2
    time_to_resolution: depends on severity and complexity of the vulnerability
  in_scope_note: >-
    "Autodesk welcomes report of vulnerabilities affecting any Autodesk-owned system, application,
    or service. This includes but is not limited to: Web applications; Desktop and mobile
    applications; API and cloud services."
  out_of_scope_note: >-
    "Versions of desktop applications that are either not officially supported or do not have the
    latest patch versions installed" — this makes the Autodesk available-product-versions policy
    part of the security contract; see lifecycle/autodesk-powermill-lifecycle.yml.
security_txt:
  served: false
  note: >-
    No /.well-known/security.txt is served on autodesk.com, www.autodesk.com or help.autodesk.com
    (403/404 — see well-known/autodesk-powermill-well-known.yml). The 200 on health.autodesk.com is
    Atlassian's Statuspage document, not Autodesk's.
evidence:
  - source: https://hackerone.com/autodesk
    kind: bug-bounty-programme
    http_status: 200
    fetched: '2026-09-06'
    detail: >-
      JSON programme record returned: id 20022, handle "autodesk", submission_state "open",
      9,675-character published policy including Response Targets, Scope and Safe Harbor sections.
  - source: https://www.autodesk.com/trust/overview
    kind: programme-declared-website
    http_status: 403
    fetched: '2026-09-06'
    detail: >-
      Named as the programme's website in the HackerOne profile record. www.autodesk.com returns 403
      to non-browser clients (Akamai bot policy) — an edge policy, not a missing page.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/autodesk-powermill-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.