Security Policy

Coordinated vulnerability disclosure for Pastebin

Reporting a vulnerability

We welcome reports from security researchers. Reports are submitted through a rotating, single-use link published in our security.txt file. Following that link opens an encrypted reporting form; the report body is encrypted at rest and is never stored in plaintext.

You may also email security@microbin.pste.us directly.

Coordinated disclosure window

We ask that you give us up to 90 days to investigate and remediate a reported issue before any public disclosure, or until a coordinated disclosure date is mutually agreed — whichever comes first. We will keep you updated through your report's status page.

In scope

  • This service and its official domains
  • The server and client (pastebin, pastebin-cli) binaries
  • The public REST, GraphQL, and web endpoints
  • Authentication, authorization, and token handling

Out of scope

  • Denial-of-service, volumetric, or rate-limit exhaustion testing
  • Social engineering, phishing, or physical attacks against staff
  • Automated scanner output without a demonstrated, reproducible impact
  • Reports affecting only unsupported or end-of-life versions
  • Attacks requiring a compromised host, rooted device, or physical access

Safe harbor

We will not pursue or support legal action against researchers who act in good faith, respect this policy, avoid privacy violations and data destruction, and give us reasonable time to respond before disclosing. Testing must stay within the scope above, use your own test data, and stop at the first sign of access to another user's data. Activity conducted consistently with this policy is considered authorized.

Acknowledgments

With your permission, we credit researchers who report valid issues on our acknowledgments page.