Vulnerability Disclosure Policy

Center for Open Science (COS) / Open Science Framework (OSF) Vulnerability Disclosure Policy


The Center for Open Science (COS) values the work of security researchers and the broader security community in helping us maintain the security and privacy of our systems and users. If you believe you have discovered a security vulnerability affecting the Open Science Framework (OSF) or another COS-operated service, we encourage you to report it responsibly.


Reporting a Vulnerability

Please submit vulnerability reports to: security@osf.io 


To help us investigate efficiently, please include:

  • A description of the vulnerability.
  • The affected URL, endpoint, or system.
  • Clear steps to reproduce the issue.
  • Any proof-of-concept code, screenshots, or logs that demonstrate the issue.
  • The potential security impact.
  • Your name and contact information (optional if you prefer to remain anonymous).

Incomplete reports may require additional information before they can be evaluated.


What to Expect

Upon receiving your report, we will:

  • Acknowledge receipt of your submission as reasonably practical.
  • Review and validate the reported issue.
  • Prioritize remediation based on severity, risk, impact, and available resources.
  • Contact you if additional information is needed.

While we appreciate responsible disclosure, we may not be able to provide detailed updates regarding investigation status, remediation timelines, or implementation details.


Scope

This policy applies to systems and services owned and operated by the Center for Open Science.


Examples include:

  • Open Science Framework (OSF)
  • Public APIs
  • COS-operated websites and services

Third-party services or vendors are outside the scope of this policy.


What we Expect From You

We ask that you:

  • Act in good faith.
  • Avoid actions that could disrupt service availability.
  • Do not intentionally access, modify, or delete data that does not belong to you.
  • Do not attempt to access another user's account or confidential information.
  • Do not exploit a vulnerability beyond what is reasonably necessary to demonstrate its existence.
  • Do not conduct denial-of-service (DoS/DDoS) attacks, spam, social engineering, phishing, or physical attacks.
  • Give us a reasonable opportunity to investigate and address reported issues before making them public.

Out of Scope

The following generally do not qualify as security vulnerabilities under this policy:

  • Missing security headers without demonstrated impact.
  • Clickjacking on pages without sensitive functionality.
  • Self-XSS.
  • Missing rate limiting without demonstrated abuse.
  • Reports based solely on automated scanner output without evidence of exploitability.
  • Best-practice recommendations that do not present a demonstrable security risk.
  • Issues affecting unsupported browsers or software versions.

Bug Bounty

The Center for Open Science does not currently operate a public bug bounty or financial reward program. We greatly appreciate responsible disclosure and the efforts of the security community in helping us improve the security of our services.

Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.