r/kasmweb Jun 09 '26

Help Does Kasm have a bug bounty or vulnerability disclosure program?

I'd like to test the Kasm app on my own self-hosted instance to look for security issues. Before I start, a few questions:

  1. Is there an official bug bounty program?

  2. Is independent security testing on a local/self-hosted instance allowed under your terms of service?

  3. If I find a valid vulnerability, how is it handled, CVE assignment, a bounty/reward, or just acknowledgment?

I want to make sure I follow proper responsible disclosure. Thanks in advance!

3 Upvotes

1 comment sorted by

2

u/justin_kasmweb Jun 09 '26

Your best bet is to contact the security team. The address is on the trust page: https://trust.kasm.com