Virix Labs · Vulnerability Disclosure

Humanbrowser Cloud Vulnerability Disclosure

Vulnerability disclosure

Virix Labs publishes a vulnerability disclosure policy for reporting security issues.

Browser AutomationCloud BrowserAI AgentsA2AMCPWeb ScrapingResidential ProxiesCAPTCHA SolvingHuman-in-the-LoopComputer UseAgent-NativeUnited Kingdom
Program:

Disclosure Policy

Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-19'
method: searched
source: https://registry.npmjs.org/@virixlabs/humanbrowser/-/humanbrowser-5.0.3.tgz (package/SECURITY.md)
probed:
- {url: 'https://humanbrowser.cloud/.well-known/security.txt', status: 404, fetched: '2026-09-19'}
- {url: 'https://humanbrowser.cloud/security.txt', status: 404, fetched: '2026-09-19'}
- {url: 'https://agent.humanbrowser.cloud/.well-known/security.txt', status: 404, fetched: '2026-09-19'}
- {url: 'https://humanbrowser.cloud/security', status: 404, fetched: '2026-09-19'}
- {url: 'https://github.com/VirixLabs/humanbrowser', status: 404, fetched: '2026-09-19', note: 'the repository that would carry SECURITY.md on the web is unreachable'}
summary: >-
  A real, provider-authored vulnerability disclosure policy exists, but it is published only inside the npm
  package (SECURITY.md in @virixlabs/humanbrowser 5.0.3) — not as RFC 9116 security.txt on either host, not
  on a /security page, and not on a reachable GitHub repository. probe-security-programs.py therefore found
  nothing on the web surface (vdp=none). The policy names a contact, an acknowledgement SLA, a remediation
  target, an in-scope list that covers the cloud service and not just the SDK, and a 90-day coordinated
  disclosure window. No bug bounty.
policy:
  contact: security@virixlabs.com
  channel: email
  acknowledgement_sla: within 48 hours
  remediation_target: remediation plan within 7 days for high-severity issues
  coordinated_disclosure_window: 90 days from report, or until a fix ships and customers have had at least 7 days to update — whichever is later
  bug_bounty: false
  bug_bounty_note: '"We do not currently run a paid bug-bounty program but will publicly credit researchers (with permission) in our changelog." No changelog is published (/changelog 404).'
  scope:
    in_scope:
    - the SDK package @virixlabs/humanbrowser
    - the MCP server shim (named as @virixlabs/mcp-human-browser — no such npm package exists; the shim ships inside @virixlabs/humanbrowser)
    - the A2A endpoint at agent.humanbrowser.cloud/a2a
    - viewer URL handling (humanbrowser.cloud/a/*)
    - the token-issuance and billing surface (humanbrowser.cloud/api/*)
    out_of_scope:
    - third-party dependencies
    - social engineering, phishing, non-technical attacks
    - denial of service ("rate limits are intentional")
    - the anti-bot evasion techniques themselves ("by design")
  quote: >-
    "If you discover a security issue in Human Browser (this SDK, the MCP server, or the cloud service at
    humanbrowser.cloud), please report it privately so we can fix it before it's disclosed publicly. Email:
    security@virixlabs.com. We will acknowledge receipt within 48 hours and aim to send a remediation plan
    within 7 days for high-severity issues."
web_surface:
  security_txt: false
  security_page: false
  note: The Privacy Policy (section 10) states TLS everywhere, API tokens hashed at rest, per-customer browser-profile isolation, and breach notification to affected users and the ICO within 72 hours; the Terms (section 3) ask users to report a suspected key compromise by email.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/humanbrowser-cloud-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.