Lightning Web Components · Vulnerability Disclosure
Lightning Web Components Vulnerability Disclosure
Vulnerability disclosure
Vulnerability disclosure posture for Lightning Web Components. The LWC project publishes its own SECURITY.md in the open-source repository naming a direct reporting address; the surrounding program (safe harbour, triage, bounty) is run by Salesforce, LWC's parent, and applies to LWC because SECURITY.md routes reports into it.
Lightning Web Components runs a coordinated vulnerability disclosure program on Hackerone.
FrontendJavaScriptLightning Web ComponentsSalesforceWeb ComponentsCustom ElementsShadow DOMOpen-SourceUI FrameworkComponent Library
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.