generated: '2026-08-27' method: searched source: https://blnkfinance.com/report-vulnerability http_status: 200 program: published: true type: coordinated-disclosure bug_bounty: false bounty_platform: null policy_url: https://blnkfinance.com/report-vulnerability contact: security@blnkfinance.com last_updated: '2025-01-04' threshold: CVSS 4.0 or higher security_txt: false security_txt_note: >- No RFC 9116 /.well-known/security.txt on any Blnk host (probed 2026-08-27: 404 on blnkfinance.com, docs.blnkfinance.com and cloud.blnkfinance.com; 401 on api.cloud.blnkfinance.com). The program is real and published as an HTML page, but a machine cannot discover it at the standard location -- the single cheapest fix available to this provider. submission_requirements: - Summary and impact - Steps to reproduce - Environment details - Proof of concept scope: in_scope_domains: - https://blnkfinance.com - https://cloud.blnkfinance.com - https://api.cloud.blnkfinance.com in_scope_platforms: - Help Scout - Discord - Slack - GitHub integrations in_scope_classes: - Authentication bypass and privilege escalation - Exposure of personally identifiable information (PII) - Unauthorized access to data outside the authenticated workspace - SQL injection and remote command execution out_of_scope: - Automated scanning activities - Social engineering, including targeting Blnk employees - Password brute force - Clickjacking on non-sensitive pages - Missing security headers without demonstrable exploitability - Issues reproducible only under highly unlikely conditions - Denial of service - Physical access attacks - Theoretical vulnerabilities without proof of concept note: >- probe-security-programs.py reported vdp=none because it looks for security.txt and for bug-bounty platform pages; Blnk publishes neither. The program was found by reading the site's own llms.txt, which lists "Report a vulnerability" under Legal.