Security Policy
Coordinated vulnerability disclosure for Pastebin
Reporting a vulnerability
We welcome reports from security researchers. Reports are submitted through a rotating, single-use link published in our security.txt file. Following that link opens an encrypted reporting form; the report body is encrypted at rest and is never stored in plaintext.
You may also email security@microbin.pste.us directly.
Coordinated disclosure window
We ask that you give us up to 90 days to investigate and remediate a reported issue before any public disclosure, or until a coordinated disclosure date is mutually agreed — whichever comes first. We will keep you updated through your report's status page.
In scope
- This service and its official domains
- The server and client (
pastebin,pastebin-cli) binaries - The public REST, GraphQL, and web endpoints
- Authentication, authorization, and token handling
Out of scope
- Denial-of-service, volumetric, or rate-limit exhaustion testing
- Social engineering, phishing, or physical attacks against staff
- Automated scanner output without a demonstrated, reproducible impact
- Reports affecting only unsupported or end-of-life versions
- Attacks requiring a compromised host, rooted device, or physical access
Safe harbor
We will not pursue or support legal action against researchers who act in good faith, respect this policy, avoid privacy violations and data destruction, and give us reasonable time to respond before disclosing. Testing must stay within the scope above, use your own test data, and stop at the first sign of access to another user's data. Activity conducted consistently with this policy is considered authorized.
Acknowledgments
With your permission, we credit researchers who report valid issues on our acknowledgments page.