Linden Lab · Vulnerability Disclosure
Linden Lab Vulnerability Disclosure
Vulnerability disclosure
Linden Lab runs a coordinated vulnerability disclosure program on Hackerone.
Virtual WorldsMetaverseGaming3DSocialVirtual EconomyDigital CurrencyMarketplaceScriptingUser Generated Content
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-25'
method: searched
source: https://wiki.secondlife.com/wiki/Security_issues
published: true
program:
name: Second Life security exploit reporting
official: true
official_evidence: >-
The page names Linden Lab's own JIRA instance (jira.secondlife.com, probed 200
on 2026-08-25) and the security@lindenlab.com mailbox, and is edit-restricted
to system administrators.
policy_url: https://wiki.secondlife.com/wiki/Security_issues
channels:
- type: issue-tracker
value: https://jira.secondlife.com/ (SEC project)
preference: preferred
note: >-
Quoted verbatim from the policy: "In the SEC project on jira.secondlife.com
(PREFERRED)". The host resolves and returns 200 as of 2026-08-25, though
Linden Lab has migrated general public issue tracking to GitHub
(github.com/secondlife/issues) and keeps a jira-archive repository.
- type: email
value: security@lindenlab.com
preference: alternate
bounty:
offered: true
amount: L$10,000
currency: L$
per: verified previously-unknown exploit
note: >-
Paid in Linden Dollars, not fiat. At the L$246.39/US$ exchange rate observed
on the LindeX feed on 2026-08-25, L$10,000 is roughly US$40. This is a real
published bounty and it is recorded as one; it is not a competitively-funded
bug bounty program.
in_scope:
- Exposes resident identity without consent
- Destroys content
- Permits unauthorized access to Second Life / Linden Lab resources
- Compromises a client or server host enabling remote control
disclosure_timeline: not published
safe_harbour: not published
platform: self-hosted (no HackerOne, Bugcrowd or Intigriti program)
platform_evidence: >-
hackerone.com/lindenlab, hackerone.com/secondlife and bugcrowd.com/lindenlab
all returned 404 on 2026-08-25.
security_txt:
published: false
detail: >-
No RFC 9116 security.txt on any Linden Lab host — see
well-known/linden-lab-well-known.yml. The disclosure policy exists but is not
machine-discoverable; an automated scanner would conclude Linden Lab has no
program, which is wrong. Publishing /.well-known/security.txt pointing at
https://wiki.secondlife.com/wiki/Security_issues would close that gap with one
file.
supporting_documentation:
- title: Technical overview of Second Life security
url: https://wiki.secondlife.com/wiki/Linden_Lab_Official:Technical_overview_of_Second_Life_security
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/linden-lab-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.