HackerOne Submission Mirror

Real form (left) · your data, copy-button per field (right)
Filing to
Status
Severity
asset weakness Open full .md
Reference exactly what hackerone.com shows you — empty, for visual comparison
Your data identical layout, pre-filled, click any field's COPY to grab
HackerOne  /   /  New report

Submit Report

Titlerequired
Briefly describe the issue. The title is the first thing the triager reads.
Asset Typerequired
Match the type the program registered for this asset. Most web targets are URL.
Assetrequired
Choose the in-scope asset this report targets. Search the wildcard root, not the specific subdomain.
Weaknessrequired
Pick the closest CWE-mapped weakness. Use the hierarchical picker.
Severityrequired
Pick a severity. The CVSS calculator opens if you want to derive one.
None
Low
Medium
High
Critical
CVSS vector
Optional. Paste a CVSS:3.0 / 3.1 vector string if you have one.
CVSS:3.0/AV:…/AC:…/PR:…/UI:…/S:…/C:…/I:…/A:…
Proof of Conceptrequired
Provide a full report: description, steps to reproduce, impact, remediation. Markdown supported.
Write
Preview
Attachments
Drop files (screenshots, logs, evidence). Max 30 MB per file.
Drag & drop files here, or click to upload
HackerOne  /   /  New report

Submit Report

Titlerequired
Briefly describe the issue. The title is the first thing the triager reads.
Asset Typerequired
Pick this exact type from H1's dropdown. Verified live against the program's published scope.
Assetrequired
Search the wildcard root in the picker — H1 shows scope roots, not children.
Weaknessrequired
Hierarchical path in H1's picker. Type to filter; H1 auto-expands the tree.
Severityrequired
Click the pill matching the severity below.
None
Low
Medium
High
Critical
CVSS vector
Paste this string into H1's CVSS calculator — it auto-derives the score.
Proof of Conceptrequired
Full markdown body of the report. Paste into H1's Write tab as-is.
Write
Preview
Attachments
Click OPEN to reveal in Explorer, then drag the file into H1's upload zone.