Security

Acknowledgements

Thank you to the researchers who responsibly disclose vulnerabilities to mop.dev. Each entry below corresponds to a confirmed, remediated finding. To add your name to this list, follow the disclosure process in our Security Reports Policy (also referenced from security.txt).

DateResearcherSeveritySummary
2026-05-20Internal auditHighIDOR in LinkInBio CRUD endpoints; fixed by the OwnedResource<R> extractor.
2026-05-21Internal auditHighSession-lifecycle, password-reset enumeration, logout open redirect, and recovery-code-replay findings; remediated in the same release.

Names appear only with the reporter's explicit consent. Want your handle changed, anonymized, or removed? Email [email protected].