Vulnerability Disclosure Program (VDP)
VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.
peloton
5
In Scope
1
Out of Scope
In-Scope Assets (5)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| cms.onepeloton.com | URL | No | ||
| cosmos-stage.onepeloton.com | URL | No | ||
| cosmos.onepeloton.com | URL | No | ||
| qa1-cms.onepeloton.com | URL | No | ||
| www.onepeloton.com | URL | No |
Out-of-Scope Assets (1)
| Asset | Category | Bounty | |
|---|---|---|---|
| Security vulnerabilities that are identified in Peloton products or in website domains owned, operated, or controlled by Peloton that are not listed above are OOS | OTHER | No |
Scope Changes (18)
Feb 25, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Added | cosmos-stage.onepeloton.com | URL | In Scope | 19:19 |
| Added | qa1-cms.onepeloton.com | URL | In Scope | 19:19 |
| Added | www.onepeloton.com | URL | In Scope | 19:19 |
| Added | security vulnerabilities that are identified in peloton products or in website domains owned, operated, or controlled by peloton that are not listed above are oos | OTHER | Out of Scope | 19:19 |
| Added | cms.onepeloton.com | URL | In Scope | 19:19 |
| Added | cosmos.onepeloton.com | URL | In Scope | 19:19 |
Feb 22, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Added | cms.onepeloton.com | URL | In Scope | 00:48 |
| Added | cosmos.onepeloton.com | URL | In Scope | 00:48 |
| Added | cosmos-stage.onepeloton.com | URL | In Scope | 00:48 |
| Added | qa1-cms.onepeloton.com | URL | In Scope | 00:48 |
| Added | www.onepeloton.com | URL | In Scope | 00:48 |
| Added | security vulnerabilities that are identified in peloton products or in website domains owned, operated, or controlled by peloton that are not listed above are oos | OTHER | Out of Scope | 00:48 |
Feb 21, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Added | cms.onepeloton.com | URL | In Scope | 19:12 |
| Added | cosmos.onepeloton.com | URL | In Scope | 19:12 |
| Added | cosmos-stage.onepeloton.com | URL | In Scope | 19:12 |
| Added | qa1-cms.onepeloton.com | URL | In Scope | 19:12 |
| Added | www.onepeloton.com | URL | In Scope | 19:12 |
| Added | security vulnerabilities that are identified in peloton products or in website domains owned, operated, or controlled by peloton that are not listed above are oos | OTHER | Out of Scope | 19:12 |