Inrupt · Vulnerability Disclosure
Inrupt Vulnerability Disclosure
Vulnerability disclosure
Inrupt runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
CompanySolidPersonal Data StoresDecentralized IdentityData PrivacyAccess ControlVerifiable CredentialsLinked DataRDFConsent ManagementData WalletsAgent InfrastructureMCPEnterprise Software
Program: Hackerone
Disclosure Policy
Security Contact
Contact
security@inrupt.com
Source
Vulnerability Disclosure
generated: '2026-08-23'
method: searched
probe: true
source: https://www.inrupt.com/security
policy_url: https://www.inrupt.com/security
advisories_url: https://www.inrupt.com/security/advisories
contact: security@inrupt.com
alternate_channel: https://inrupt.atlassian.net/servicedesk
team: Inrupt Product Security Incident Response Team (PSIRT)
bug_bounty: false
bug_bounty_note: >-
No HackerOne, Bugcrowd or Intigriti programme was found. Reporting is direct to PSIRT by email or
Service Desk ticket; no bounty is offered.
security_txt: false
security_txt_note: >-
No /.well-known/security.txt is served on www.inrupt.com, docs.inrupt.com or any ESS service host
(all probed 2026-08-23, all 404). The disclosure policy exists but is not machine-discoverable at
the RFC 9116 location.
commitments:
- Acknowledgement of report receipt
- Communication of estimated time for resolution
- Notification of fix
out_of_scope_research:
- Denial of Service (DoS) of any kind
- Automated security tools
- Accessing, or attempting to access, data that does not belong to you
- Destroying or corrupting data that does not belong to you
severity_scoring:
framework: CVSS v3.1
reference: https://www.first.org/cvss/calculator/3.1
note: >-
The stated internal scoring framework is CVSS v3.1, though the most recent published advisory
(NRPT-2025-002) is scored with CVSS v4.0.
third_party_cve_handling: >-
Inrupt updates third-party components within regularly scheduled release cycles to the newest
compatible version available during development, and states that a vulnerability in a third-party
component does not necessarily translate to a vulnerability in Inrupt software. PSIRT accepts
questions about the applicability of a third-party CVE.
advisories:
published: true
count: 13
identifier_scheme: NRPT-YYYY-NNN
contents: date, advisory ID, severity, CVSS vector, related CVE, summary, affected products
recent:
- id: NRPT-2025-002
date: '2025-08-08'
title: ESS ingress-nginx Server-Snippet Vulnerability
severity: CRITICAL
cvss: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N (9.1)'
related_cve: CVE-2021-25742
affected: ESS versions prior to 2.5.1 and 2.3.6
- id: NRPT-2025-001
date: '2025-06-30'
title: Weak Password Derivation in Message Encryption
- id: NRPT-2024-003
date: '2024-12-02'
title: Authentication Token Exclusivity in ESS Endpoint Configuration
- id: NRPT-2024-002
date: '2024-03-06'
title: OpenID Token Manipulation Vulnerability in ESS Access Grant, Storage and Query Services
- id: NRPT-2024-001
date: '2024-01-14'
title: ESS Authorization Off-by-One Error in Shared Status Lists
earliest: NRPT-2020-001 (2020-05-15, Authentication Token Capture-Replay)
evidence:
- source: https://www.inrupt.com/security
kind: disclosure page
http_status: 200
keywords:
- vulnerability
- PSIRT
- security@inrupt.com
- source: https://www.inrupt.com/security/advisories
kind: advisory index
http_status: 200
- source: https://www.inrupt.com/security/inrupt-security-public-asc
kind: published PGP public key (listed in sitemap.xml)
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/inrupt-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.