Xpeng · Vulnerability Disclosure

Xpeng Vulnerability Disclosure

Vulnerability disclosure

Xpeng runs a coordinated vulnerability disclosure program on Hackerone.

CompanyTechnologyAutomotiveElectric VehiclesSmart MobilityAutonomous DrivingChina
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

xpeng-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-21'
method: searched
probe: true
policy:
- https://security.xiaopeng.com/
contact: []
program: XPeng Security Emergency Response Center (小鹏安全应急响应中心)
notes: >-
  XPeng operates a Chinese-style Security Emergency Response Center (SRC) at
  security.xiaopeng.com (title: 小鹏安全应急响应中心, app bundle xp-src-platform),
  linked from the www.xiaopeng.com homepage footer. The platform is a
  JavaScript application; submission requires an account on the platform.
  No /.well-known/security.txt is published on xpeng.com or xiaopeng.com
  (the xiaopeng.com path returns a soft 404), and no HackerOne/Bugcrowd/
  Intigriti program was found for the xpeng.com domain by the mechanical probe.
evidence:
- source: https://security.xiaopeng.com/
  kind: security-response-center
  http_status: 200
  title: 小鹏安全应急响应中心
- source: https://www.xiaopeng.com/
  kind: homepage-footer-link
  http_status: 200