Lightning Web Components · Vulnerability Disclosure

Lightning Web Components Vulnerability Disclosure

Vulnerability disclosure

Vulnerability disclosure posture for Lightning Web Components. The LWC project publishes its own SECURITY.md in the open-source repository naming a direct reporting address; the surrounding program (safe harbour, triage, bounty) is run by Salesforce, LWC's parent, and applies to LWC because SECURITY.md routes reports into it.

Lightning Web Components runs a coordinated vulnerability disclosure program on Hackerone.

FrontendJavaScriptLightning Web ComponentsSalesforceWeb ComponentsCustom ElementsShadow DOMOpen-SourceUI FrameworkComponent Library
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

lightning-web-components-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-27'
method: searched
source: https://github.com/salesforce/lwc/blob/master/SECURITY.md
provider: Lightning Web Components
providerId: lightning-web-components
description: >-
  Vulnerability disclosure posture for Lightning Web Components. The LWC project publishes its own
  SECURITY.md in the open-source repository naming a direct reporting address; the surrounding
  program (safe harbour, triage, bounty) is run by Salesforce, LWC's parent, and applies to LWC
  because SECURITY.md routes reports into it.
disclosure:
  published: true
  policy_url: https://github.com/salesforce/lwc/blob/master/SECURITY.md
  policy_status: 200
  contact_email: security@salesforce.com
  first_party: true
  statement: >-
    "Please report any security issue to security@salesforce.com as soon as it is discovered. This
    library limits its runtime dependencies in order to reduce the total cost of ownership as much
    as can be, but all consumers should remain vigilant and have their security stakeholders review
    all third-party products (3PP) like this one and their dependencies."
  security_txt:
    served: false
    note: >-
      No RFC 9116 /.well-known/security.txt is served on lwc.dev (HTTP 500 catch-all),
      developer.salesforce.com (HTTP 403 bot challenge) or www.salesforce.com (HTTP 404). The
      disclosure contact is published in the repository SECURITY.md instead.
program:
  scope: parent-brand
  name: Salesforce Responsible Disclosure / Bug Bounty
  disclosure_page: https://www.salesforce.com/company/disclosure/
  disclosure_page_status: 200
  security_site: https://security.salesforce.com/
  security_site_status: 200
  bug_bounty:
    platform: HackerOne
    url: https://hackerone.com/salesforce
    status: 200
    invite_only: true
    note: >-
      Salesforce operates an invitation-based bug bounty; researchers submit suspected
      vulnerabilities via Hackforce and track progress there. Salesforce publicly reports having
      paid out over $18.9M across roughly 30,600 reported potential vulnerabilities.
  safe_harbor:
    published: true
    statement: >-
      "Salesforce pledges not to initiate legal action against researchers for penetrating or
      attempting to penetrate our systems as long as they adhere to this policy."
  researcher_recognition: https://security.salesforce.com/security-research-contributors/
supply_chain:
  dependabot: true
  dependabot_evidence: .github/dependabot.yml present in salesforce/lwc
  note: >-
    Dependency bumps appear as first-class entries in the LWC release stream (js-yaml, vite,
    postcss, fast-xml-parser, systeminformation across v9.3.4–v9.4.0), which is the visible output
    of that automation.
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/lightning-web-components-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.