Dronecode Foundation · Vulnerability Disclosure
Dronecode Vulnerability Disclosure
Vulnerability disclosure
Dronecode Foundation runs a coordinated vulnerability disclosure program on Hackerone.
DronesUAVRoboticsMAVLinkPX4AutopilotAerial RoboticsgRPCOpen SourceLinux Foundation
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-06'
method: searched
source: >-
https://raw.githubusercontent.com/PX4/PX4-Autopilot/main/SECURITY.md (HTTP 200) and
https://github.com/PX4/PX4-Autopilot/security/policy (HTTP 200), read 2026-09-06.
probe-security-programs.py reported vdp=none because it probes web hosts and
/.well-known/security.txt, and this policy lives in the repository — found by hand.
provider: Dronecode Foundation
providerId: dronecode
has_program: true
program_type: coordinated-disclosure
bug_bounty: false
bounty_note: No bug bounty, no HackerOne/Bugcrowd/Intigriti program. Reporters are credited, not paid.
policy_url: https://github.com/PX4/PX4-Autopilot/security/policy
policy_file: https://github.com/PX4/PX4-Autopilot/blob/main/SECURITY.md
scope:
project: PX4 Autopilot
note: >-
The policy covers PX4 Autopilot. MAVSDK, MAVLink and QGroundControl publish NO SECURITY.md —
checked 2026-09-06, all three return 404 for /contents/SECURITY.md. There is no
Foundation-wide disclosure policy and no /.well-known/security.txt on any host
(see well-known/dronecode-well-known.yml — 404 on all eight).
intake:
channel: GitHub Security Advisories
method: >-
"Report a Vulnerability" on the Security tab of github.com/PX4/PX4-Autopilot. No email address is
published for intake; the fallback is emailing the release managers listed in MAINTAINERS.md.
security_txt: false
response_commitments:
acknowledgement: 7 days
quote: 'Acknowledgment: The maintainer team will acknowledge your report within 7 days.'
triage: Severity and impact assessed, next steps communicated.
disclosure: >-
Coordinated with the reporter. "We follow responsible disclosure practices and will credit
reporters in the advisory unless they request anonymity."
escalation: Follow up by emailing the release managers if no acknowledgement within 7 days.
supported_versions:
- version: 1.17.x
supported: true
- version: 1.16.x
supported: true
- version: < 1.16
supported: false
notable:
ai_assisted_discovery_policy: >-
PX4 publishes an explicit AI-assisted-discovery clause, aligned with the Linux kernel security
policy — findings produced with AI assistance must be treated as PUBLIC and submitted as a pull
request rather than a private advisory, because the same bug tends to surface across multiple
researchers on the same day. The reproducer is the exception and must never be posted publicly:
"it works against vehicles in the field until the fix ships." The policy also asks that a
reproducer be demonstrated against SITL (`make px4_sitl`) before filing. This is one of the very
few provider security policies in this catalog that addresses agent-generated vulnerability
reports at all.
secure_development_practices:
- Peer code review required on all changes.
- clang-tidy static analysis on every pull request, warnings treated as errors.
- Daily fuzzing pipeline (Google fuzztest) over MAVLink message handling and GNSS driver protocol parsing.
- Input validation on all external inputs — MAVLink messages, RC signals, sensor data.
- Compiler hardening — -Wall -Werror, stack protectors.
gaps:
- No /.well-known/security.txt (RFC 9116) on any of the eight hosts probed.
- No policy for MAVSDK, MAVLink or QGroundControl — three of the five hosted projects.
- No Foundation-level policy at dronecode.org; /security returns 404.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/dronecode-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.