Koala · Vulnerability Disclosure

Koala Io Vulnerability Disclosure

Vulnerability disclosure

Koala publishes a vulnerability disclosure policy for reporting security issues.

Buyer IntentVisitor IdentificationDe-anonymizationEnrichmentGo-To-MarketSales IntelligenceB2B
Program:

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
source: https://getkoala.com/security/vulnerability/
url: https://getkoala.com/security/vulnerability/
http_status: 200
program:
  published: true
  type: responsible-disclosure
  bug_bounty: true
  bounty_platform: none (direct to Koala)
  bounty_terms: >-
    "For valid vulnerabilities considered in-scope with a CVSS score of 4 or higher,
    may be eligible for a financial reward. The specific amount will be determined
    based on the severity and impact of the issue."
  contact_email: security@getkoala.com
  contact_note: >-
    Published behind Cloudflare email obfuscation on the page; decoded from the
    page's data-cfemail attribute.
  safe_harbor_stated: false
  disclosure_expectation: >-
    "we kindly request that you do not make the vulnerability public before reporting
    it to us, and give us adequate time to address the issue"
  report_requirements:
  - Summary of the issue and its potential impact
  - Detailed breakdown of the steps to replicate
  - Environment details (OS, browser version)
  - Proof-of-concept code where available
scope:
  in_scope:
  - https://getkoala.com
  - https://app.getkoala.com
  - https://api.getkoala.com
  out_of_scope:
  - Automated scanning of any kind
  - Social engineering, especially targeting Koala employees
  - Denial of Service (DoS) attacks of any kind
  - Attacks requiring physical access to the victim's device
  - Theoretical attacks without proof of exploitability
  - Man-in-the-middle attacks
  - Clickjacking on pages with no sensitive actions
  - High-privilege users sabotaging or defacing their own workspace
  - Logic bugs bypassing free-plan limits or unlocking paid features
  - Missing best practices in CSP, email DNS records, or cookies
  rules_of_engagement:
  - Test only on your own account or with explicit permission
  - Avoid privacy violations, unauthorized data access, and data destruction
  - Make a good-faith effort to avoid service interruption or degradation
  - Do not escalate or expand access if remote access is obtained
security_txt:
  served: false
  note: >-
    No RFC 9116 /.well-known/security.txt on any Koala host — the program is
    HTML-only. robots.txt (https://getkoala.com/robots.txt, HTTP 200) explicitly
    carries `Disallow: /security/vulnerability/`, so the disclosure page is
    deliberately excluded from crawlers, which is why an automated security.txt probe
    finds nothing.
evidence:
- url: https://getkoala.com/security/vulnerability/
  status: 200
  fetched: '2026-08-13'
- url: https://getkoala.com/robots.txt
  status: 200
  fetched: '2026-08-13'
  detail: 'User-agent: * / Allow: / / Disallow: /security/vulnerability/'
- url: https://getkoala.com/.well-known/security.txt
  status: 404
  fetched: '2026-08-13'
lifecycle_warning: >-
  Koala was acquired by Cursor and shuts down 2026-09-30. Two of the three in-scope
  hosts were already failing on 2026-08-13 — app.getkoala.com returns HTTP 530
  (Cloudflare 1016) and api.getkoala.com returns HTTP 400 {"error": "Koala ingest
  suspended"} — so the program is effectively unreachable for testing even though the
  page still serves.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/koala-io-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.