How to report security vulnerabilities in Chatwoot
Chatwoot is looking forward to working with security researchers worldwide to keep Chatwoot and our users safe. If you have found an issue in our systems/applications, please reach out to us.
We use GitHub for security issues that affect our project. If you believe you have found a vulnerability, please disclose it via this form.
This will enable us to review the vulnerability, fix it promptly, and reward you for your efforts.
If you have any questions about the process, contact security@chatwoot.com.
Please try your best to describe a clear and realistic impact for your report, and please don’t open any public issues on GitHub or social media; we’re doing our best to respond through GitHub as quickly as possible.
Please use the email for questions related to the process. Disclosures should be done via GitHub.
Version | Supported |
---|---|
latest | ️✅ |
< latest | ❌ |
Please do not perform testing against Chatwoot production services. Use a self-hosted instance
to perform tests.
We consider the following vulnerabilities as high priority:
We consider the following out of scope, though there may be exceptions:
If you are unsure about the scope, please create a report.
Chatwoot team triages the issues in GitHub weekly. We’re doing our best to respond through GitHub as quickly as we can, so please don’t open any public issues on GitHub or social media and avoid duplicate reports over emails.
After triage, the team will start working on the issue based on the following severity and timelines:
Severity | Timeline |
---|---|
Critical (P0) | ️ 7 Days |
High | 30 Days |
Medium | 60 Days |
Low | 90 Days |
While we don’t currently have a formal bug bounty program, we do recognize and appreciate security researchers who help us improve Chatwoot’s security:
If you need assistance with security reporting:
Thank you for keeping Chatwoot and our users safe. 🙇
Your efforts help us maintain a secure platform for thousands of businesses worldwide. We appreciate the time and expertise you contribute to making Chatwoot better for everyone.
Remember: Security is a shared responsibility. Together, we can make Chatwoot safer for everyone.