vulns.co
/
GKData.io MCP

HackerOne · 1 min read

Starbucks

Paid Bounty

Open current program Scope capture

What this record establishes

Scope capture

Published asset rows were captured. The full policy and eligibility were not individually reviewed.

Directory row 415; Active program checkbox checked; Bounties minimum displayed $100. Positive displayed minimum supports paid bounty listing. Policy and live submission availability unverified.

Published asset scope

Snapshot captured 2026-10-03. Scope status: Captured.

In scope · 10 published rows
AssetTypeGroup / eligibility
www.starbucksreserve.comURLBounty eligible: Yes
www.starbucks.caURLBounty eligible: Yes
www.starbucks.comURLBounty eligible: Yes
app.starbucks.comURLBounty eligible: Yes
openapi.starbucks.comURLBounty eligible: Yes
secureui.starbucks.comURLBounty eligible: Yes
Subdomain Takeover (SDTO)OTHERBounty eligible: Yes
com.starbucks.mobilecardGOOGLE_PLAY_APP_IDBounty eligible: Yes
com.starbucks.mystarbucksAPPLE_STORE_APP_IDBounty eligible: Yes
Other assetsOTHERBounty eligible: No
Out of scope · 6 published rows
AssetTypeGroup / eligibility
apply.starbucks.comURLBounty eligible: No
careers.starbucks.comURLBounty eligible: No
lsstar.starbucks.comURLBounty eligible: No
athome.starbucks.comURLBounty eligible: No
istarbucks.co.krURLBounty eligible: No
TeavanaOTHERBounty eligible: No

Capture limits

  • Only the published asset table was captured; program rules and eligibility still require individual review.

Live policy and platform eligibility still require review.

Sources and collection identity

  1. Official program page Primary source · reviewed 2026-10-03
  2. Published scope source Primary source · reviewed 2026-10-03

Appears in Discovery, Bounty. No identity match is inferred from a shared company name.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software