Critical
¥2,000 – ¥5,000
Remote code execution, sandbox escape, account takeover, cross-tenant data access
We welcome security researchers to test the ZCode desktop client, CLI, IDE plugins and official online services and report security or privacy vulnerabilities.
Severity is rated by real-world impact. The ZCode security team makes the final rating.
¥2,000 – ¥5,000
Remote code execution, sandbox escape, account takeover, cross-tenant data access
¥500 – ¥2,000
Unauthorised access to sensitive data, privilege escalation, SSRF, arbitrary file read or write
¥100 – ¥500
Limited information disclosure, CSRF, reflected XSS, path traversal
¥20 – ¥100
Clickjacking, missing security configuration, verbose errors
High-quality reports, working PoCs and new attack chains can earn an additional reward.
The Z.ai Security Response Center (ZSRC) receives and handles security vulnerabilities and privacy issues in ZCode products and services. We welcome security researchers to report vulnerabilities and help us improve product security.
Reports are submitted through the Vulbox platform, which performs the initial review. The ZCode security team confirms the rating, follows the fix and pays the reward.