Last updated: 6 June 2026
Email security@chessmovesai.com with:
For high-sensitivity findings (credential exposure, RCE, SQLi), please encrypt your report using our PGP key at /.well-known/pgp-key.txt.
| Target | Type |
|---|---|
| chessflows.com (web app) | XSS, CSRF, SQLi, auth bypass, IDOR, privilege escalation |
| chessflows.com/api/* (REST API) | Broken access control, injection, information disclosure |
| WebSocket endpoint (wss://chessflows.com) | Message injection, DoS, auth bypass |
| Authentication flows | Token forgery, session fixation, account takeover |
| File upload / media handling | Path traversal, stored XSS, SSRF via upload |
| Category | Reason |
|---|---|
| Denial-of-service (volumetric) | Infrastructure/network attacks, not application bugs |
| Social engineering / phishing | Not a code vulnerability |
| Physical access attacks | Out of scope |
| Third-party services (Stripe, Anthropic, Lichess) | Report directly to those vendors |
| Automated scanner output without PoC | Low signal without evidence of exploitability |
| Missing security headers on non-sensitive pages | Not reportable without exploit |
| Self-XSS (requires tricking yourself) | No practical impact |
| Outdated TLS versions without downgrade PoC | Low practical risk |
ChessMoves AI does not currently operate a paid bug bounty programme. However, we offer:
| Severity | Examples |
|---|---|
| Critical | RCE, SQLi with data exfil, full account takeover without user interaction |
| High | IDOR exposing private data, stored XSS, auth bypass, mass account enumeration |
| Medium | Reflected XSS, CSRF, rate limit bypass on sensitive endpoints |
| Low | Information disclosure (non-sensitive), open redirect, minor config issue |
ChessMoves AI will not pursue legal action against researchers who:
We consider good-faith security research conducted under this policy to be authorised access. We will not file complaints with law enforcement for activity within these rules.
We are grateful to the following researchers who have responsibly disclosed vulnerabilities to us:
Machine-readable disclosure policy: /.well-known/security.txt