PentestingHere
Log in Join

Tesla

Tesla on Bugcrowd · Bugcrowd Active

Official page

Scope

At a glance

  • Maximum payout: $100,000
  • Public disclosure: Not allowed
  • Managed by the platform: Yes
  • Safe harbour: Partial

In scope

  • *.tesla.cn
  • *.tesla.services
  • https://apps.apple.com/us/app/tesla/id582007913
  • *.tesla.com
  • *.teslamotors.com
  • Any host verified to be owned by Tesla Motors Inc. (domains/IP space/etc.)
  • *.solarcity.com
  • *.teslainsuranceservices.com
  • https://play.google.com/store/apps/details?id=com.teslamotors.tesla&hl=en_US&gl=US
  • Tesla Energy hardware you own
  • Tesla vehicle hardware that you own

Out of scope

  • employeefeedback.tesla.com
  • energysupport.tesla.com (you can report vulnerabilities to bugbounty.zoho.com)
  • https://engage.tesla.com/
  • *.engage.tesla.com
  • feedback.tesla.com
  • feedback.teslamotors.com
  • ir.tesla.com
  • ir.teslamotors.com
  • mkto.teslamotors.com
  • shop.eu.teslamotors.com
  • service.tesla.com/docs/*
  • service.tesla.cn/docs/*
  • Any domains from acquisitions, such as maxwell.com
  • Any other third-party websites hosted by non-Tesla entities

Imported from the public directory. Always confirm scope on the official program page before testing.

Is it worth your time?

Read the community feedback

0 reviews rating communication, triage, payouts and whether it suits beginners.

Open feedback