- CHANNEL:SECURITY
- SIGNAL:RECEIVED
- ORIGIN:REDACTED
Responsible Disclosure.
Found a weakness? Report it privately and we will work with you to fix it. Security researchers are welcome here.
DISCLOSURE CHANNEL
- POLICY
- RESPONSIBLE DISCLOSURE
- SECURITY.TXT
- /.well-known/security.txt
- RESPONSE
- BEST EFFORT
- BOUNTY
- NOT OFFERED
REPORT TO
Reporting a vulnerability
If you believe you have found a security vulnerability in GLHF.RUN, we want to hear from you. Please report it privately so we can address it before it is publicly disclosed.
Email security@glhf.run with a clear description, steps to reproduce, and any relevant proof-of-concept. Please give us reasonable time to respond before public disclosure.
Scope
The GLHF.RUN website and its interactive tools are in scope. Because the site collects no accounts and no personal data, most classic data-exfiltration classes do not apply. We still care about issues like content injection, supply-chain risks, and configuration weaknesses.
What to expect
We will acknowledge legitimate reports, keep you informed of remediation progress, and credit researchers who wish to be credited once an issue is resolved.
Please do not
Do not run automated scanners that degrade service, access or modify data that is not yours, or perform social-engineering or physical attacks. Good-faith research conducted within these guidelines is welcome.
LAST UPDATED: 2026.08.01