Please report your finding using the form below. Upon receiving your report, we will investigate and respond to you as soon as possible. Please do not discuss any vulnerabilities (even resolved ones) outside of the program without express consent from the organization.
Alternatively you can send an email to security@larksuite.com. Participation in our bug bounty program requires complying with the full bug bounty policy below.
When reporting vulnerabilities, please consider (1) attack scenario / exploitability, and (2) security impact of the bug. The following issues are considered out of scope: