generated: '2026-08-13' method: searched source: https://getkoala.com/security/vulnerability/ url: https://getkoala.com/security/vulnerability/ http_status: 200 program: published: true type: responsible-disclosure bug_bounty: true bounty_platform: none (direct to Koala) bounty_terms: >- "For valid vulnerabilities considered in-scope with a CVSS score of 4 or higher, may be eligible for a financial reward. The specific amount will be determined based on the severity and impact of the issue." contact_email: security@getkoala.com contact_note: >- Published behind Cloudflare email obfuscation on the page; decoded from the page's data-cfemail attribute. safe_harbor_stated: false disclosure_expectation: >- "we kindly request that you do not make the vulnerability public before reporting it to us, and give us adequate time to address the issue" report_requirements: - Summary of the issue and its potential impact - Detailed breakdown of the steps to replicate - Environment details (OS, browser version) - Proof-of-concept code where available scope: in_scope: - https://getkoala.com - https://app.getkoala.com - https://api.getkoala.com out_of_scope: - Automated scanning of any kind - Social engineering, especially targeting Koala employees - Denial of Service (DoS) attacks of any kind - Attacks requiring physical access to the victim's device - Theoretical attacks without proof of exploitability - Man-in-the-middle attacks - Clickjacking on pages with no sensitive actions - High-privilege users sabotaging or defacing their own workspace - Logic bugs bypassing free-plan limits or unlocking paid features - Missing best practices in CSP, email DNS records, or cookies rules_of_engagement: - Test only on your own account or with explicit permission - Avoid privacy violations, unauthorized data access, and data destruction - Make a good-faith effort to avoid service interruption or degradation - Do not escalate or expand access if remote access is obtained security_txt: served: false note: >- No RFC 9116 /.well-known/security.txt on any Koala host — the program is HTML-only. robots.txt (https://getkoala.com/robots.txt, HTTP 200) explicitly carries `Disallow: /security/vulnerability/`, so the disclosure page is deliberately excluded from crawlers, which is why an automated security.txt probe finds nothing. evidence: - url: https://getkoala.com/security/vulnerability/ status: 200 fetched: '2026-08-13' - url: https://getkoala.com/robots.txt status: 200 fetched: '2026-08-13' detail: 'User-agent: * / Allow: / / Disallow: /security/vulnerability/' - url: https://getkoala.com/.well-known/security.txt status: 404 fetched: '2026-08-13' lifecycle_warning: >- Koala was acquired by Cursor and shuts down 2026-09-30. Two of the three in-scope hosts were already failing on 2026-08-13 — app.getkoala.com returns HTTP 530 (Cloudflare 1016) and api.getkoala.com returns HTTP 400 {"error": "Koala ingest suspended"} — so the program is effectively unreachable for testing even though the page still serves.