Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

nubank

BugcrowdView on Bugcrowd
RawAI Enhanced
9
In Scope
4
Out of Scope

In-Scope Assets (9)

AssetCategoryBountyQuick Links
https://apps.apple.com/br/app/nubank-conta-e-cart%C3%A3o/id814456780IOSNo-
https://nubank.com.br/OTHERNo-
https://nubank.com.coOTHERNo-
https://nubank.com.mxOTHERNo-
https://play.google.com/store/apps/details?id=com.nu.production&hl=pt_BR&gl=US&pli=1ANDROIDNo
https://www.nuinvest.com.br/URLNo
prod-*.nu.com.coURLNo
prod-*.nu.com.mxURLNo
prod-*.nubank.com.brURLNo
Out-of-Scope Assets (4)
AssetCategoryBounty
*.nat-a.nubank.com.brOTHERNo
*.nuinternational.comURLNo
NuCommunity endpoints (BR, MX, CO)URLNo
international.nubank.com.brURLNo