Responsible Vulnerability Disclosure Policy
Last updated: April 23, 2026
We value the security research community. If you discover a vulnerability on Tour Frontier, please report it responsibly.
Found a security issue?
Report it to our security team — we respond within 48 hours.
| Researcher | Finding | Severity | Date |
|---|---|---|---|
AC Alex Chen @alexcsec | Reflected XSS in destination search parameter | Medium | March 2026 |
SO Sarah Okafor sarahokafor.dev | Open redirect in OAuth callback flow | Medium | January 2026 |
ML Marcus Lindberg @mlindberg_sec | Information disclosure in API error responses | Low | November 2025 |
PS Priya Sharma priyasec.io | CSRF token bypass in trip sharing endpoint | High | September 2025 |
JW James Wilson @jwilson_0x | Rate limiting bypass on password reset | Medium | July 2025 |
Ready to help us stay secure?
Read our full policy above and send your findings to security@tourfrontier.com
We use cookies to enhance your experience
We use cookies to personalize content, analyze traffic, and improve our services. By clicking "Accept All", you consent to our use of cookies. Cookie Policy & Privacy Policy