HungryPanda · Vulnerability Disclosure

Hungrypanda Vulnerability Disclosure

Vulnerability disclosure

HungryPanda runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyFood DeliveryDeliveryMarketplaceRestaurantsGroceryLogisticsE-CommerceMerchantsPoint of Sale
Program: Hackerone

Disclosure Policy

Security Contact

Contact
emaillog@hungrypandagroup.com
Contact
noteListed on the SRC footer as 专用邮箱 (dedicated mailbox); the address is served through Cloudflare email-protection obfuscation and was decoded from the page token /cdn-cgi/l/email-protection#711d1e163119041f16030801101f151016031e04015f121e1c.
Contact
wechat_official_accounttrue

Source

Vulnerability Disclosure

hungrypanda-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-22'
method: searched
source: https://hpsrc.hungrypanda.co/
program:
  name: HungryPanda Security Response Center (熊猫外卖安全响应中心 / HP·SRC)
  type: self-hosted-vdp-with-bounty
  url: https://hpsrc.hungrypanda.co/
  status: active
  language: zh-Hans
  operator: HungryPanda
  note: 'Self-hosted vulnerability response centre on the company''s own subdomain — not HackerOne,
    Bugcrowd or Intigriti. Reachable anonymously; submitting a report requires a researcher account.'
submission:
  url: https://hpsrc.hungrypanda.co/user.php?m=user&c=post&a=add
  requires_account: true
  http_status: 200
contact:
  email: log@hungrypandagroup.com
  note: 'Listed on the SRC footer as 专用邮箱 (dedicated mailbox); the address is served through
    Cloudflare email-protection obfuscation and was decoded from the page token
    /cdn-cgi/l/email-protection#711d1e163119041f16030801101f151016031e04015f121e1c.'
  wechat_official_account: true
policies:
- title: 2026开启收录漏洞的通告【阶段二】 (2026 vulnerability intake notice, phase two)
  url: https://hpsrc.hungrypanda.co/index.php?m=&c=page&a=view&id=4
  http_status: 200
  summary: 'Intake rules — reports must describe impact rather than symptoms, duplicates and
    unverified automated-scanner output are rejected, the finding must be a first submission and
    not already public, and destructive testing or data tampering is forbidden. Points to a
    separate severity-scoring and reward standard (《收取漏洞类型及评分标准》).'
- title: 关于非主要业务漏洞的收录与赏金说明 (non-core-business vulnerability intake and bounty note)
  url: https://hpsrc.hungrypanda.co/index.php?m=&c=page&a=view&id=5
  http_status: 200
  summary: 'Separates core from non-core business scope; explicitly names interface/API security
    issues and vulnerabilities in the company''s own in-house code as in scope.'
bounty:
  offered: true
  currency: CNY
  mechanism: 安全币 (security coins) redeemable for cash rewards
  published_tiers: [100, 300, 600, 1000]
  note: Tiers read verbatim from the rewards panel on the SRC home page.
security_txt:
  served: false
  probes:
  - url: https://www.hungrypanda.co/.well-known/security.txt
    status: 404
  - url: https://hpsrc.hungrypanda.co/.well-known/security.txt
    status: 404
  note: 'No RFC 9116 security.txt is served on any HungryPanda host, so the SRC is discoverable
    only from the site footer — a one-line fix worth taking to the provider.'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hungrypanda-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.