Submit Vulnerability Report

File a vulnerability report through the tracked intake.

Authentication

AuthorizationBearer

Bearer authentication of the form Bearer <token>, where token is your auth token.

Headers

X-API-Keystring or nullOptional

Request

This endpoint expects an object.
descriptionstringRequired1-20000 characters
titlestringRequired1-200 characters
affected_componentstring or nullOptional<=200 characters
attachment_base64string or nullOptional<=15000000 characters
attachment_content_typestringOptional<=50 charactersDefaults to image/png
attachment_heightinteger or nullOptional0-20000
attachment_widthinteger or nullOptional0-20000
impactstring or nullOptional<=5000 characters
reporter_contactstring or nullOptional<=255 characters
reproduction_stepsstring or nullOptional<=20000 characters
severityenumOptional

Impact of the reported issue.

Deliberately the same four values as QaSeverity so the canonical severity→Linear-priority map (linear_service._SEVERITY_TO_PRIORITY) applies unchanged — agent-authored, QA-widget and VDP issues all land in Linear with identical priorities.

Allowed values:

Response

Successful Response
acknowledgement_targetstring
idstringformat: "uuid"
statusstring

Errors

401
Unauthorized Error
403
Forbidden Error
422
Unprocessable Entity Error
429
Too Many Requests Error
500
Internal Server Error