Inrupt · Vulnerability Disclosure

Inrupt Vulnerability Disclosure

Vulnerability disclosure

Inrupt runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanySolidPersonal Data StoresDecentralized IdentityData PrivacyAccess ControlVerifiable CredentialsLinked DataRDFConsent ManagementData WalletsAgent InfrastructureModel Context ProtocolEnterprise Software
Program: Hackerone

Disclosure Policy

Security Contact

Contact
security@inrupt.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-23'
method: searched
probe: true
source: https://www.inrupt.com/security
policy_url: https://www.inrupt.com/security
advisories_url: https://www.inrupt.com/security/advisories
contact: security@inrupt.com
alternate_channel: https://inrupt.atlassian.net/servicedesk
team: Inrupt Product Security Incident Response Team (PSIRT)
bug_bounty: false
bug_bounty_note: >-
  No HackerOne, Bugcrowd or Intigriti programme was found. Reporting is direct to PSIRT by email or
  Service Desk ticket; no bounty is offered.
security_txt: false
security_txt_note: >-
  No /.well-known/security.txt is served on www.inrupt.com, docs.inrupt.com or any ESS service host
  (all probed 2026-08-23, all 404). The disclosure policy exists but is not machine-discoverable at
  the RFC 9116 location.
commitments:
- Acknowledgement of report receipt
- Communication of estimated time for resolution
- Notification of fix
out_of_scope_research:
- Denial of Service (DoS) of any kind
- Automated security tools
- Accessing, or attempting to access, data that does not belong to you
- Destroying or corrupting data that does not belong to you
severity_scoring:
  framework: CVSS v3.1
  reference: https://www.first.org/cvss/calculator/3.1
  note: >-
    The stated internal scoring framework is CVSS v3.1, though the most recent published advisory
    (NRPT-2025-002) is scored with CVSS v4.0.
third_party_cve_handling: >-
  Inrupt updates third-party components within regularly scheduled release cycles to the newest
  compatible version available during development, and states that a vulnerability in a third-party
  component does not necessarily translate to a vulnerability in Inrupt software. PSIRT accepts
  questions about the applicability of a third-party CVE.
advisories:
  published: true
  count: 13
  identifier_scheme: NRPT-YYYY-NNN
  contents: date, advisory ID, severity, CVSS vector, related CVE, summary, affected products
  recent:
  - id: NRPT-2025-002
    date: '2025-08-08'
    title: ESS ingress-nginx Server-Snippet Vulnerability
    severity: CRITICAL
    cvss: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N (9.1)'
    related_cve: CVE-2021-25742
    affected: ESS versions prior to 2.5.1 and 2.3.6
  - id: NRPT-2025-001
    date: '2025-06-30'
    title: Weak Password Derivation in Message Encryption
  - id: NRPT-2024-003
    date: '2024-12-02'
    title: Authentication Token Exclusivity in ESS Endpoint Configuration
  - id: NRPT-2024-002
    date: '2024-03-06'
    title: OpenID Token Manipulation Vulnerability in ESS Access Grant, Storage and Query Services
  - id: NRPT-2024-001
    date: '2024-01-14'
    title: ESS Authorization Off-by-One Error in Shared Status Lists
  earliest: NRPT-2020-001 (2020-05-15, Authentication Token Capture-Replay)
evidence:
- source: https://www.inrupt.com/security
  kind: disclosure page
  http_status: 200
  keywords:
  - vulnerability
  - PSIRT
  - security@inrupt.com
- source: https://www.inrupt.com/security/advisories
  kind: advisory index
  http_status: 200
- source: https://www.inrupt.com/security/inrupt-security-public-asc
  kind: published PGP public key (listed in sitemap.xml)

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/inrupt-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.