Upstox · Vulnerability Disclosure

Upstox Vulnerability Disclosure

Vulnerability disclosure

Upstox runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served.

CompanyFinancial ServicesStock TradingBrokerageMarket DataInvestingCapital MarketsMutual FundsAlgorithmic TradingIndia
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-02'
method: searched
source: https://upstox.com/bug-bounty/
name: Upstox Bug Bounty Program
program:
  type: self-hosted
  name: Upstox Bug Bounty Program
  url: https://upstox.com/bug-bounty/
  platform: none
  note: >-
    Upstox runs its own bug bounty rather than using HackerOne, Bugcrowd or Intigriti. Submissions go
    through a Google-account-gated vulnerability submission form linked from the program page; the page
    states the security team replies within a couple of working days and that reward amount and severity
    are decided case by case.
  security_txt: false
  security_txt_note: >-
    https://upstox.com/.well-known/security.txt returned HTTP 403 (an origin object-store AccessDenied
    XML body, not an RFC 9116 document) — Upstox publishes no security.txt on any of its hosts.
severity_levels:
- level: critical
  examples:
  - Pre-authentication reflected or DOM XSS
  - Stored XSS generally accessible by users
  - Command injection
  - Deserialization attacks
  - Forced browsing with supplied credentials or session tokens of logged-in users
  - SQL injection
  - Forced browsing leading directly to customer data
  - Account takeover through logic flaw or inappropriate session handling
- level: high
  examples:
  - Post-authentication reflected or DOM XSS
  - CSRF involving purchases, sales or funds transfers
  - OTP bypass
  - Logic flaws allowing manipulation of data
  - Directory browsing enabling bulk sensitive data download
  - Session fixation
  - Logic flaws resulting in potential privilege escalation
- level: medium
  examples:
  - Directory browsing enabling isolated data download
  - Logic flaws causing data integrity issues without privilege escalation
- level: low
  examples:
  - Account enumeration where rate limiting is not enforced
  - Logic flaws with no privilege escalation or data integrity impact
- level: informational
  examples:
  - Directory browsing with no critical files available
  - Disclosure of non-critical business information
  - Internal asset enumeration or disclosure
out_of_scope:
- Content Security Policy not deployed
- Text injection
- CSRF (except the cases listed under high), CORS, HSTS
- HttpOnly flag not set on cookies
- Outdated software with no public exploit or not exploitable in the current configuration
- Missing SPF, DKIM and DMARC records
- Missing HTTP security headers that do not lead to an exploitable condition
- DoS / DDoS
- UAT and DEV environments
- Session expiration
- Rate limiting
- Origin IP disclosure
- EXIF data
- The bug bounty form and its services
- Clickjacking / X-Frame-Options
- Phishing-based attacks
in_scope_domains:
- smallcases.upstox.com
- streak.upstox.com
- community.upstox.com
- upstox.com/uplearn
- learn-lms.upstox.com
- help.upstox.com
- employee-benefits.upstox.com
- webstories.upstox.com
disclosure_rules:
- Researchers must keep findings confidential and must not disclose publicly or to other organizations.
- No copying, sharing, transferring or replicating of customer data.
- Testing must not affect any commercial or trading service at Upstox.
- No social engineering of Upstox customers or staff.
- Findings must be from the latest stable version, new, reproducible and remotely exploitable in a standard configuration.
evidence:
- source: https://upstox.com/bug-bounty/
  http_status: 200
  kind: bug bounty program page (live fetch)
- source: https://upstox.com/trust-security/
  http_status: 200
  kind: responsible disclosure section linking the bug bounty program
- source: https://upstox.com/.well-known/security.txt
  http_status: 403
  kind: security.txt probe (absent)

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/upstox-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.