Target · Vulnerability Disclosure

Target Vulnerability Disclosure

Vulnerability disclosure

Target publishes a full Vulnerability Disclosure Policy at https://security.target.com/vdp/ (HTTP 200) covering its guest-facing online services. It states an explicit safe-harbour clause, a rules-of- engagement list, a coordinated-disclosure requirement, third-party forwarding, and researcher recognition after remediation. There is no bug-bounty platform (no HackerOne / Bugcrowd / Intigriti program was found) and no monetary reward is offered — this is disclosure, not bounty.

Target runs a coordinated vulnerability disclosure program on Hackerone.

Fortune 100E-CommerceRetailProductInventoryStoresOrder
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-27'
method: searched
probe: true
source: https://security.target.com/vdp/
policy_url: https://security.target.com/vdp/
program_type: vulnerability-disclosure-policy
managed_platform: null
bug_bounty: false
safe_harbor: true
public_disclosure: coordinated
description: >-
  Target publishes a full Vulnerability Disclosure Policy at https://security.target.com/vdp/ (HTTP
  200) covering its guest-facing online services. It states an explicit safe-harbour clause, a rules-of-
  engagement list, a coordinated-disclosure requirement, third-party forwarding, and researcher
  recognition after remediation. There is no bug-bounty platform (no HackerOne / Bugcrowd / Intigriti
  program was found) and no monetary reward is offered — this is disclosure, not bounty.
terms:
  safe_harbor: >-
    "Target will not take legal action against you related to any activities conducted in a manner
    consistent with this Policy and otherwise in good faith."
  coordinated_disclosure: >-
    "public disclosure of vulnerabilities will only be authorized after the vulnerability has been
    addressed and requires the express written consent of Target."
  third_party_forwarding: >-
    "In the event the report you submit involves a third-party vendor, we will forward your report to
    that vendor."
  recognition: >-
    "After a vulnerability has been validated and fixed, we will seek to allow researchers to be
    recognized whenever possible."
  scope: Target's guest-facing online services.
  submission: Web form on the policy page.
evidence:
- source: https://security.target.com/vdp/
  http_status: 200
  content_type: text/html
  kind: vulnerability disclosure policy
  keywords:
  - report a security vulnerability
  - safe harbor
  - program rules
  - coordinated disclosure
- source: https://security.target.com/
  http_status: 200
  kind: security landing page linking to the policy
gaps:
- id: no-security-txt
  detail: >-
    RFC 9116 security.txt is NOT served on any Target host. /.well-known/security.txt returned 404 on
    www.target.com, api.target.com, redsky.target.com, corporate.target.com, tech.target.com,
    security.target.com and both IAM issuers, and 200-with-an-HTML-shell on developer.target.com.
    Target has the policy but not the discovery file, so an automated scanner cannot find it. Adding a
    three-line security.txt pointing at https://security.target.com/vdp/ is the cheapest fix in this
    entire profile.
  probed:
  - url: https://www.target.com/.well-known/security.txt
    status: 404
  - url: https://security.target.com/.well-known/security.txt
    status: 404
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/target-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.