Please do not open a public GitHub issue for a security problem.
Report it through our vulnerability disclosure policy at https://infisical.com/vulnerability-disclosure.
Please include what you found, where, how to reproduce it, what an attacker could achieve, and how you would like to be credited.
The full scope of the program, along with our safe harbour and coordinated disclosure terms, is set out in the policy linked above.
This is a vulnerability disclosure program, not a bug bounty. It offers acknowledgement and public credit rather than payment.
Infisical's paid bug bounty is a separate private, invitation-only program covering Infisical Cloud. It is not open to public submissions, and reports made through this repository are not eligible for its rewards. Strong reports here are a good route to an invitation.
Security fixes ship in the latest release. We always recommend running the latest version of Infisical. If you self-host, upgrading promptly is the fastest way to stay protected.
For compliance documentation, security questionnaires, penetration-test reports and SOC 2 requests, use security@infisical.com. That address is not a vulnerability intake channel.