generated: '2026-08-26' method: searched source: https://plotly.com/security/ program: type: security-contact bug_bounty: false bug_bounty_platform: null policy_url: https://plotly.com/security/ contact_email: security@plotly.com disclosure_page: https://plotly.com/security/ safe_harbour_statement: not published scope_statement: not published response_sla: not published statement: >- From https://plotly.com/security/: "we shut down the offending process/endpoint and stop the bleeding, after which we let you know without undue delay and start patching the issue." practices: - Regular vulnerability assessments - Proactive security updates - Multi-layered security measures security_txt: served: false probed: - url: https://plotly.com/.well-known/security.txt status: 404 - url: https://dash.plotly.com/.well-known/security.txt status: 200 note: SPA catch-all HTML shell, not an RFC 9116 document note: >- A published security@ address that is not discoverable at /.well-known/security.txt is the concrete gap here - an agent or scanner has no machine-readable route to it. in_product_security_response: note: >- Plotly ships security fixes through the open-source changelog rather than a CVE feed. Example: Dash 4.4.1 (2026-07-21) fixed background callbacks trusting client-supplied job/cacheKey parameters, which allowed an unauthenticated client to terminate an arbitrary process or read and delete result-cache entries (PR #3902). source: https://github.com/plotly/dash/blob/dev/CHANGELOG.md x-evidence: - url: https://plotly.com/security/ http_status: 200 fetched: '2026-08-26' - url: https://plotly.com/.well-known/security.txt http_status: 404 fetched: '2026-08-26'