Hyundai · Vulnerability Disclosure

Hyundai Vulnerability Disclosure

Vulnerability disclosure

Hyundai runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

AutomobilesCarsConnected VehiclesMobilityVehiclesAutomotiveTelematicsElectric VehiclesVehicle DataSouth Korea
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
HAEE_Security@hyundai-autoever.eu

Source

Vulnerability Disclosure

hyundai-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-13'
method: searched
probe: true
source: https://www.hyundai.com/.well-known/security.txt
contact:
  - HAEE_Security@hyundai-autoever.eu
policy_url: null
bug_bounty: null
acknowledgements: null
encryption: null
canonical: null
preferred_languages:
  - en
  - de
expires: '2026-12-31T23:59:59Z'
expires_valid: true
rfc9116: true
evidence:
  - source: https://www.hyundai.com/.well-known/security.txt
    kind: security.txt (live probe)
    status: 200
    content_type: text/plain; charset=UTF-8
    date: '2026-09-13'
    file: well-known/hyundai-security.txt
findings:
  - >-
    The security.txt is minimal but valid — Contact, Expires and Preferred-Languages only.
    It omits the optional Policy, Acknowledgments, Encryption and Canonical fields, so a
    researcher gets an address but no published disclosure process or safe-harbour terms.
  - >-
    The contact address belongs to Hyundai AutoEver Europe (hyundai-autoever.eu) and the
    preferred languages are English and German, indicating the file is operated by the
    European IT subsidiary rather than by the Korean developer platform. A vulnerability in
    the Hyundai Developers connected-car API has no published reporting channel of its own.
  - >-
    No security.txt on developers.hyundai.com, console.developers.hyundai.com or
    prd.kr-ccapi.hyundai.com — all 404. See well-known/hyundai-well-known.yml.
  - >-
    No bug bounty programme found on HackerOne, Bugcrowd or Intigriti for Hyundai Motor
    Company, and no vulnerability-disclosure page on the developer portal.
  - >-
    The developer portal does publish a narrow security-adjacent contact path:
    developers@hyundai.com for technical support, and the console guide directs partners to
    that address if a Client ID / Client Secret is exposed.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hyundai-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.