We appreciate responsible reports that help keep github.com/sumup/acp and its users secure.
Users should run the latest release to receive current stability and security fixes.
Do not report vulnerabilities in public GitHub issues or pull requests. Report them privately through SumUp's bug bounty program.
To request access to the private HackerOne program, contact bugbounty at sumup dot com.
The SumUp security team will triage the report and determine whether it is eligible for a bounty.
- Keep the vulnerability confidential until it has been addressed.
- Do not compromise user privacy, system integrity, or availability while testing.
- If you are unsure whether something is a vulnerability, report it privately.