Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
MongoDB Bug Bounty
MongoDB HackerOne $100–$25,000
2 more reviews needed for a grade
Reported practices
+ Fast payout 1 report
Auto-closes valid reports 1 report
Went silent / ghosted 1 report
Slow to pay 1 report
Disputes valid scope 1 report
Downgrades severity 1 report
Lowballed the bounty 1 report
Write a review Claim this company profile

Work at MongoDB? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Reviews

1 published
One click remote code execution - Working as intended. Then reopened
neutral

Triage overall left me relatively disappointed, but by equal measures, relived. I reported a remote code execution to this program in May, the H1 analyst team reviewed and downgraded the severity from critical to high on account of double-counting the UI:R component, in the CVSS. Two weeks after the report was closed as informative quote: "The team has confirmed that the current behavior is working as expected given the trust model of the application." After thorough, and repeated follow up and technical rebuttal the company corrected their initial decision and awarded a bounty payout. The timeline on this report was May 23 → July 9, a whole 47 days, with 27 of those days, it sitting as Informative. Ultimately their turnaround and decision to award the bounty was appreciated and I will continue to engage with them where appropriate. However, to any new researchers on H1, do not pursue this program before you have the signal to request mediation, as without it, you will be entirely at the mercy of the program.

via HackerOne reports 1 paid $2k – $10k 1st reply Within 3 days resubmit yes recommends no skill Advanced
− Auto-closes valid reports − Downgrades severity + Fast payout − Went silent / ghosted − Lowballed the bounty − Disputes valid scope − Slow to pay
Month Sev Outcome Why closed Bounty
May 2026 Critical Informative Something else $2k – $10k
Maliq Barnard ✓ verified · Aug 11, 2026 · Share ↗ 0 helpful
0 comments

Log in to comment