Z.ai Security Response Center

We welcome security researchers to test the ZCode desktop client, CLI, IDE plugins and official online services and report security or privacy vulnerabilities.

Bug bounty

Severity is rated by real-world impact. The ZCode security team makes the final rating.

Critical

¥2,000 – ¥5,000

Remote code execution, sandbox escape, account takeover, cross-tenant data access

High

¥500 – ¥2,000

Unauthorised access to sensitive data, privilege escalation, SSRF, arbitrary file read or write

Medium

¥100 – ¥500

Limited information disclosure, CSRF, reflected XSS, path traversal

Low

¥20 – ¥100

Clickjacking, missing security configuration, verbose errors

High-quality reports, working PoCs and new attack chains can earn an additional reward.

About ZSRC

The Z.ai Security Response Center (ZSRC) receives and handles security vulnerabilities and privacy issues in ZCode products and services. We welcome security researchers to report vulnerabilities and help us improve product security.

Reports are submitted through the Vulbox platform, which performs the initial review. The ZCode security team confirms the rating, follows the fix and pays the reward.

In scope

  • Desktop clientmacOS, Windows, Linux
  • CLIZCode command-line tool
  • IDE plugins & extensionsOfficial plugins and extensions
  • Online servicesAccounts, plans and other services

How reports are handled

  1. 1SubmitSend details and reproduction material through Vulbox
  2. 2Initial reviewVulbox checks validity and filters duplicates
  3. 3RatingThe ZCode security team reproduces the issue and sets the severity
  4. 4FixCritical and High issues are fixed first
  5. 5RewardPaid per the reward plan once the rating is confirmed