Bug Bounty & Vulnerability Disclosure

~ Ethical Security Research & Responsible Disclosure ~

Help keep Yukisbox bulletproof. We offer full safe harbor protection and swift triage.

🐾 Security Pledge: Found a vulnerability? Report it directly to security@yukiapi.site or @Z0iiw. We acknowledge reports within 12 hours and never pursue legal action against ethical researchers!

Responsible Disclosure Guidelines

To maintain eligibility for our safe harbor and vulnerability acknowledgment program, researchers must:

Program Scope & Severity Tiers

Critical (P1)

Remote Code Execution (RCE), Authentication Bypass, Unauthenticated Database Exfiltration.

High (P2)

Stored XSS across download links, Insecure Direct Object References (IDOR), API Key disclosure.

Medium (P3)

CSRF on sensitive endpoints, CORS misconfigurations allowing cross-origin credential theft.

Low (P4)

Subtle rate-limiting bypasses, verbose error traces, non-sensitive metadata leaks.

Submission Template

[Vulnerability Report] Target: https://yukiapi.site Endpoint: /api/upload / /file/{uid} Vulnerability Type: [e.g. IDOR, Stored XSS, SSRF] Severity: [Critical / High / Medium / Low] Steps to Reproduce: 1. ... 2. ... 3. ... Impact: ... Proof of Concept (cURL / Request / Script): ...

Contact Security Team

Send completed reports to security@yukiapi.site or reach out directly to lead architect SUDEEPBOTS on Telegram at @Z0iiw.