vulns.co
/
GKData.io MCP

Back to Platforms

Node.js HackerOne

Security reports for the Node.js runtime go through the HackerOne program.

Tags: vendor, hackerone, opensource

Program model
Vendor on HackerOne
Regions
Global
Payout
Varies by program

Specialties: opensource, runtime

How to approach it

Scope first, and confirm whether rewards are currently funded. The project has said bounty money can be paused while HackerOne stays the reporting channel.

  • Read the Node.js threat model before you file a runtime issue.
  • Third-party npm packages are not this program. Report those to the maintainer.

Official links