Welcome to our Coordinated Vulnerability Disclosure channel.
If you conduct vulnerability research in good faith and in accordance with this policy, we consider your research to be authorized. We will work with you to understand and resolve the issue quickly, and Robovision will not initiate legal action against you regarding your research.
We aim to acknowledge receipt and begin initial triage of submitted reports within 24 hours. Validated reports involving active exploits are immediately escalated to our response team for containment and regulatory notification.
Give us a reasonable timeframe to remediate the vulnerability before publicly disclosing any details.
Do not access, modify, or delete customer data. Only use your own test accounts during research.
Do not attempt social engineering, spear-phishing, or physical attacks against our staff.
In-scope submissions:
- Remote Code Execution (RCE) on processing servers or agents.
- Authentication/authorization bypass on the platform dashboard or APIs.
- Unintended access to trained AI model files or customer datasets.
- Malicious file uploads (e.g., image parsing exploits, buffer overflows in image processing libraries).
- Injection flaws (SQLi, Command Injection) within API parameters or web interfaces
Out-of-scope submissions
In order to filter out unnecessary reports by humans, the site needs to inform the reporters of the following:
The following types of reports are outside the scope of our Coordinated Vulnerability Disclosure (CVD) program and will be closed automatically:
- Volumetric & Denial of Service Attacks: Network-level DoS/DDoS, or sending large volumes of image/video data designed solely to exhaust server compute or bandwidth.
- Physical & Optical Adversarial Manipulation: Adversarial or physical optical tricks designed to alter model inference results without exploiting the underlying software stack.
- Unverified Automated Scans: Raw outputs or PDF exports from automated security scanners without a manual, step-by-step Proof of Concept (PoC).
- Theoretical Model Limitations: General statistical misclassifications inherent to computer vision models that do not lead to unauthorized data access, privilege escalation, or system compromise.
- Any routine bugs
- Any feature suggestions or improvements
- Theoretical configurations that have no active exploit