generated: '2026-09-04' method: searched source: https://github.com/appsmithorg/appsmith/blob/release/SECURITY.md name: Appsmith vulnerability disclosure program: type: coordinated-disclosure bug_bounty: false bounty_note: 'Explicitly stated: "At this juncture, we don''t have a bug bounty program. We are a small team trying to solve a big problem."' reporting: primary: GitHub private vulnerability reporting url: https://github.com/appsmithorg/appsmith/security/advisories/new email: security@appsmith.com email_source: https://security.appsmith.com/ policy_url: https://github.com/appsmithorg/appsmith/blob/release/SECURITY.md advisories: github: https://github.com/appsmithorg/appsmith/security/advisories repository: https://github.com/appsmithorg/security-advisory note: A dedicated appsmithorg/security-advisory repository holds advisories for Appsmith products. Recent CVEs are also referenced inline in the codebase (GHSA-v6jh-fx3m-7xhw on the OpenAPI docs endpoints, GHSA-qrgm-h8c4-jjf7 on rate-limit key spoofing). security_txt: published: false note: /.well-known/security.txt returns 404 on appsmith.com, www.appsmith.com and docs.appsmith.com, and an SPA shell on app.appsmith.com. Publishing one would make this policy machine-discoverable. safe_harbor: published: false note: No explicit safe-harbor language in SECURITY.md. evidence: - url: https://raw.githubusercontent.com/appsmithorg/appsmith/release/SECURITY.md http_status: 200 - url: https://github.com/appsmithorg/appsmith/security/advisories http_status: 200 - url: https://www.appsmith.com/.well-known/security.txt http_status: 404