TextMaster · Vulnerability Disclosure

Textmaster Vulnerability Disclosure

Vulnerability disclosure

TextMaster runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyTranslationLocalizationLanguage ServicesCopywritingProofreadingMachine TranslationContent ProductionTranslation MemoryGlossaryEcommerce LocalizationProduct Information ManagementWebhookAuthenticationSoftware-as-a-Service
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy

Security Contact

Contact
bounty@textmaster.com
Contact
{"security_txt" => nil}

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-17'
method: searched
probe: true
source: >-
  https://github.com/textmaster/bugbounty +
  https://raw.githubusercontent.com/textmaster/bugbounty/main/README.md +
  https://raw.githubusercontent.com/textmaster/bugbounty/main/SECURITY.md +
  https://raw.githubusercontent.com/textmaster/bugbounty/main/disclosure-guidelines.md
checked: '2026-08-17'
summary: >-
  TextMaster runs a real, paid, publicly documented bug bounty program — and runs it in an unusual
  place: a public GitHub repository, github.com/textmaster/bugbounty, using GitHub Security
  Advisories as the intake channel instead of HackerOne, Bugcrowd or Intigriti. Three policy
  documents are published (README, SECURITY.md, disclosure-guidelines.md), the maximum reward is
  $5,000, severity is scored with CVSS 3.0 by a published formula, and api.textmaster.com is
  explicitly named as in-scope "Core". This is a substantially more complete disclosure posture than
  most providers of this size publish. It is entirely invisible to machine discovery, because there
  is no /.well-known/security.txt on any host.
program:
  exists: true
  paid: true
  kind: public bug bounty
  platform: GitHub Security Advisories (self-hosted, no third-party bounty platform)
  intake_url: https://github.com/textmaster/bugbounty/security/advisories
  intake_probed_status: 200
  repository: https://github.com/textmaster/bugbounty
  repository_probed_status: 200
  clarification_contact: bounty@textmaster.com
  submission_steps:
  - Go to https://github.com/textmaster/bugbounty
  - Click the Security tab
  - Click the Advisories sub-menu
  - Click "New draft security advisory"
  - Fill in the report following the published guidelines
  - Create the draft security advisory
  severity_calculator: GitHub built-in (CVSS 3.0 vector string)
  severity_caveat_from_provider: >-
    "Note that currently, GitHub does not support Temporal and Environmental scores. Therefore, your
    severity score might be lowered down after submitting your draft according to our policy."
policy:
- https://github.com/textmaster/bugbounty/blob/main/SECURITY.md
- https://github.com/textmaster/bugbounty/blob/main/disclosure-guidelines.md
- https://github.com/textmaster/bugbounty/blob/main/README.md
contact:
- bounty@textmaster.com
- security_txt: null
rewards:
  currency: USD
  maximum: 5000
  maximum_condition: a critical vulnerability
  minimum: 100
  scoring_standard: CVSS 3.0 (Base, Temporal and Environmental scores)
  formula: 'b = N x (C^n) where n = 3.0 and N = bmax / (Cmax)^n'
  published_table:
  - {cvss: 1, bounty: 100}
  - {cvss: 2, bounty: 100}
  - {cvss: 3, bounty: 135}
  - {cvss: 4, bounty: 320}
  - {cvss: 5, bounty: 625}
  - {cvss: 6, bounty: 1080}
  - {cvss: 7, bounty: 1715}
  - {cvss: 8, bounty: 2560}
  - {cvss: 9, bounty: 3645}
  - {cvss: 10, bounty: 5000}
  bonus_clause: >-
    "In rare cases, we may choose to accept and award a bonus for an issue with a CVSS score of 0
    when we see a high potential for future security impact, and make a change as a result of the
    report."
  duplicate_fairness_clause: >-
    "Reward any report mistakenly closed as invalid if we later receive and reward the same bug
    reported by someone else. In these situations, we will reward both security researchers." And:
    "Pay the bounty difference to the duplicate reporter in case the new report demonstrates a
    higher CVSS score."
scope:
  core:
  - {host: app.textmaster.com, env: Core, max_severity: Critical, reward_eligible: true}
  - {host: api.textmaster.com, env: Core, max_severity: Critical, reward_eligible: true}
  core_definition: '"TextMaster Core includes app.textmaster.com and api.textmaster.com."'
  api_in_scope: true
  api_in_scope_significance: >-
    The API host is named as first-class Core scope at Critical severity with full reward
    eligibility. That is a direct, provider-published statement that the API surface this repo
    catalogues is covered by the security program.
  non_core:
  - {host: textmaster.com, env: Non-core, max_severity: Medium, reward_eligible: false}
  - {host: '*.textmaster.com', env: Non-core, max_severity: Medium, reward_eligible: false}
  - {host: 3rd party apps, env: Non-core, max_severity: Low, reward_eligible: false}
  out_of_scope:
  - {host: docs.textmaster.com, reason: Operated by a third party}
  - {host: images.textmaster.com, reason: Operated by a third party}
  - {host: status.textmaster.com, reason: Operated by a third party}
  - host: storage-proxy.textmaster.com
    reason: >-
      "TextMaster allows clients to upload any file they want on our storage network. Being able to
      upload a file is not a vulnerability, this is the intended functionality."
  - {host: '*.subtitly.io', reason: null}
  - {host: '*.textmaster.co', reason: null}
  - {host: '*.textmaster.io', reason: null}
  - {host: '*.textmasters.com', reason: null}
  out_of_scope_note: >-
    Vulnerabilities on unlisted domains "will be accepted, but are ineligible for a reward."
  technology_in_scope: >-
    "All software components that are used within the TextMaster application may be exploited in
    your attack, including bugs in the Ruby interpreter (MRI), the Ruby on Rails framework, as well
    as third party libraries that we use (such as Ruby gems)." This also confirms the platform is a
    Ruby on Rails application.
  adjacent_property_note: >-
    The out-of-scope list names three sibling domains TextMaster owns or has owned — subtitly.io,
    textmaster.co and textmaster.io — plus a typo-defence entry (textmasters.com). subtitly.io is a
    subtitling product, which is a real product lead this profile does not otherwise capture.
commitments:
  provider_pledges:
  - Reply to all reports
  - Be as transparent as possible, answering all inquiries about our report decisions
  - Award fair value bounties based on CVSS scores
  - Only close reports as Non Applicable when the issue is a listed Known or Ineligible Issue, or lacks evidence
  safe_harbor_stated: false
  safe_harbor_note: >-
    No explicit legal safe-harbour / authorized-testing clause was found. The guidelines set
    behavioural expectations (respect the rules, respect privacy, be patient, do no harm) but do not
    promise not to pursue researchers acting in good faith.
  disclosure_embargo: >-
    "Do not disclose any issues publicly before they have been resolved." No coordinated-disclosure
    deadline is stated.
  licensing_terms: >-
    Submitted content is licensed to TextMaster under the MIT License, and reporters "irrevocably
    waive all moral rights" in it.
restrictions:
- Not open to minors, individuals on sanctions lists, or residents of sanctioned countries
- Commercial scanners are prohibited (e.g. Nessus)
- Employees are excluded (they use an internal program)
- 'Do not contact TextMaster support about the program; use bounty@textmaster.com'
- Reports must be filed as soon as the vulnerability is validated
known_issues_excluded:
- Tab nabbing
- Password reset tokens not expiring when changing email address
- Reflected XSS requiring full control of an HTTP header (Referer, Host, etc.)
- CSRF for login or logout, unless chained to demonstrate impact
- CAPTCHA replay attacks
ineligible_issue_classes:
- Distributed Denial of Service
- Content spoofing
- Social engineering, including phishing
- Email flooding
- Unconfirmed reports from automated vulnerability scanners
- Disclosure of server or software version numbers
- Generic Host header attacks without evidence of a remote victim
evidence:
- source: https://github.com/textmaster/bugbounty
  kind: public repository
  status: 200
  checked: '2026-08-17'
- source: https://raw.githubusercontent.com/textmaster/bugbounty/main/README.md
  kind: program overview
  status: 200
  bytes: 1997
  checked: '2026-08-17'
- source: https://raw.githubusercontent.com/textmaster/bugbounty/main/SECURITY.md
  kind: security policy (scope, rewards, rules)
  status: 200
  bytes: 12015
  checked: '2026-08-17'
- source: https://raw.githubusercontent.com/textmaster/bugbounty/main/disclosure-guidelines.md
  kind: disclosure guidelines
  status: 200
  checked: '2026-08-17'
- source: https://github.com/textmaster/bugbounty/security/advisories
  kind: intake channel
  status: 200
  checked: '2026-08-17'
discoverability_gap:
  finding: >-
    The program is excellent and effectively undiscoverable by machine. There is no
    /.well-known/security.txt on api.textmaster.com, www.textmaster.com, fr.textmaster.com or
    docs.textmaster.com (32 probes, zero hits — see well-known/textmaster-well-known.yml), and no
    /security page on the marketing site (https://www.textmaster.com/security 301s to the homepage).
    A researcher or scanner has no path to bounty@textmaster.com except finding the GitHub org by
    hand.
  remediation_for_provider: >-
    Publish an RFC 9116 security.txt at https://api.textmaster.com/.well-known/security.txt with
    Contact: mailto:bounty@textmaster.com and
    Policy: https://github.com/textmaster/bugbounty/blob/main/SECURITY.md. This is a single static
    file and it would close the gap entirely.
  probed:
  - {url: 'https://api.textmaster.com/.well-known/security.txt', status: 404, checked: '2026-08-17'}
  - {url: 'https://www.textmaster.com/.well-known/security.txt', status: 403, checked: '2026-08-17'}
  - {url: 'https://www.textmaster.com/security', status: 301, redirects_to: 'https://www.textmaster.com/', checked: '2026-08-17'}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/textmaster-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.