SecurityAcknowledgements
Thank you to the researchers who responsibly disclose vulnerabilities to mop.dev. Each entry below corresponds to a confirmed, remediated finding. To add your name to this list, follow the disclosure process in our Security Reports Policy (also referenced from security.txt).
| Date | Researcher | Severity | Summary |
|---|---|---|---|
| 2026-05-20 | Internal audit | High | IDOR in LinkInBio CRUD endpoints; fixed by the OwnedResource<R> extractor. |
| 2026-05-21 | Internal audit | High | Session-lifecycle, password-reset enumeration, logout open redirect, and recovery-code-replay findings; remediated in the same release. |
Names appear only with the reporter's explicit consent. Want your handle changed, anonymized, or removed? Email [email protected].