Feedback on the Vercel bug reporting and vulnerability assessment process

I reported a bug that could cause millions in losses for Vercel. However, they assigned someone to evaluate my report who didn’t understand anything I said and ultimately claimed it was normal. I would like to know if I can post on Twitter how to do this, since it’s normal and you’re assuming the loss. I only asked for a reward for discovering and reporting it; you need to improve the quality of critical analysis by your employees who review bug reports. The employee kept asking me for HTTP requests, and I was informing them that exploiting the bug didn’t require HTTP requests.}

Do you have a link to this? Was this in the community platform, or elsewhere?

It was on HackerOne.

Can you share a link?

Como adquirir um?

The link to the HackerOne post :slight_smile:

The thread on HackerOne is private; I can’t share it. I can only take screenshots.

Can’t you create a channel so I can show you how to share it, instead of here in the post where anyone can see it?