Flagsmith · Vulnerability Disclosure

Flagsmith Vulnerability Disclosure

Vulnerability disclosure

Flagsmith runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

Feature FlagsRemote ConfigRelease ManagementA/B TestingExperimentationSegmentationDeveloper ToolsDevOpsOpen SourceSoftware-as-a-ServiceMCPAgent Ready
Program: Hackerone

Disclosure Policy

Security Contact

Contact
emailsupport@flagsmith.com
Contact
noteWritten in the policy as "support[at]flagsmith[dot]com" (obfuscated against scrapers). There is no dedicated security@ address and no PGP key.

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-17'
method: searched
source: https://github.com/Flagsmith/flagsmith/security/policy
policy_url: https://github.com/Flagsmith/flagsmith/security/policy
raw_url: https://raw.githubusercontent.com/Flagsmith/flagsmith/main/SECURITY.md
evidence:
- {url: 'https://raw.githubusercontent.com/Flagsmith/flagsmith/main/SECURITY.md', status: 200}
- {url: 'https://github.com/Flagsmith/flagsmith/security/policy', status: 200}
- {url: 'https://flagsmith.com/.well-known/security.txt', status: 404}
- {url: 'https://api.flagsmith.com/.well-known/security.txt', status: 404}
- {url: 'https://docs.flagsmith.com/.well-known/security.txt', status: 404}
checked: '2026-09-17'
published: true
contact:
  email: support@flagsmith.com
  note: >-
    Written in the policy as "support[at]flagsmith[dot]com" (obfuscated against scrapers). There is
    no dedicated security@ address and no PGP key.
security_txt: false
bug_bounty:
  program: false
  platform: null
  note: No HackerOne, Bugcrowd or Intigriti programme was found.
safe_harbor: false
disclosure_policy:
  stated_process:
  - Assess the risk
  - Identify the remediation
  - Implement and deploy a fix to the SaaS platform, Docker images and source code
  - Create a GitHub issue labelled `Security` where appropriate
  response_sla: null
  scope: null
  note: >-
    Short, real, and honest about what it is: a process commitment for the open-source project and
    the SaaS platform, not a formal VDP. No acknowledgement window, no severity SLA, no defined
    scope, no safe-harbour language, and no coordinated-disclosure timeline. Everything it does say,
    though, it says plainly — including that a fix lands in the Docker images and source, which
    matters to the large self-hosted population this product has.
  gap: >-
    The policy is discoverable only from the GitHub repository. A /.well-known/security.txt on
    flagsmith.com pointing at it would cost one file and is the single cheapest security-posture
    improvement available here; all six hosts probed return 404.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/flagsmith-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.