Disclaimer: This report reflects the submitter's account. It has not been independently verified unless marked Verified. The company may dispute this claim.
Scam Alert: livedune.com — LiveDune — Multiple Vulnerabilities Fixed, but No Final Response After Four Months
Company / Program: livedune.com
Platform: Self-Hosted · Severity: high · Scam type: ignored
Published:
Reported by: AliAbbas
I reported several security vulnerabilities to LiveDune, including an IDOR, XSS, and a race condition.
The vulnerabilities were subsequently fixed by LiveDune. However, after initially responding to my reports, the company stopped providing meaningful updates despite multiple follow-ups from my side.
The entire process has now been ongoing for approximately four months.
My concern is not that the vulnerabilities were ignored technically they appear to have been fixed. The issue is the lack of communication and failure to provide a final response or clear closure for my reports.
I submitted multiple security reports to LiveDune.
The reports included:
Timeline
April 21, 2026 — Initial Vulnerability Reports
IDOR involving /reactCompany/userSet, allowing low-privileged access to functionality that should have been restricted.
Race Condition involving a user invite endpoint with potential billing-related impact.
XSS vulnerability affecting LiveDune.
The email records show the reports were submitted on April 21, 2026.
June 11, 2026 — First Follow-Up
After receiving no response for an extended period, I followed up with LiveDune and requested an update regarding my reports.
At this point, I had already been waiting for a significant amount of time.
July 7, 2026 — LiveDune Asked Me to Resend the Reports
LiveDune responded:
“Hello! Could you please resend the reports?”
I resent/provided the requested information and continued the communication.
July 10, 2026 — LiveDune Confirmed the Reports
LiveDune then acknowledged my submission and stated:
“Report received. Our security team will review within 7 business days. We will contact you as soon as the assessment is complete.”
I therefore expected to receive a final assessment within the stated timeframe.
After July 10, 2026 — No Final Response
After the seven-business-day period passed, I still did not receive the promised update.
I sent multiple follow-ups asking for the status of my reports.
I also noticed that the reported vulnerabilities had been fixed.
I contacted LiveDune again because, although the issues appeared to have been resolved, I had still received no proper response regarding my reports.
August 17, 2026 — Four Months Later
As of August 17, 2026, approximately four months after my initial reports, the vulnerabilities have been fixed, but I still have not received a proper final response or clear closure regarding my submissions.
My Concern
I appreciate that LiveDune fixed the vulnerabilities I reported. However, fixing a vulnerability should not be the end of communication with the person who responsibly disclosed it.
I would have appreciated a simple response confirming:
That the vulnerabilities were reviewed.
That they were fixed.
The final status of each report.
Whether the reports were eligible for a bounty or recognition.
That the reports were officially closed.
Instead, after the initial responses, I had to repeatedly follow up without receiving a final resolution.
Overall Experience
Vulnerabilities reported: IDOR, XSS, Race Condition
Vulnerabilities fixed: Yes, based on my observation
Initial response: Yes
Promised review period: 7 business days
Final response received: No
Follow-ups sent: Multiple
Total timeline: Approximately 4 months
Conclusion
I am publishing this report to document my experience with LiveDune's vulnerability disclosure process.
I want to make it clear that my criticism is primarily about communication and report closure, not the technical remediation. LiveDune did fix the vulnerabilities I reported, which I appreciate.
However, after four months and multiple follow-ups, I believe researchers deserve a clear final response when they responsibly report security vulnerabilities.
If LiveDune provides a final explanation or update regarding these reports, I am happy to update this post accordingly.
Report a Scam Use the Submit tab to file a detailed report with evidence.
🛡
Security Issues Found a vulnerability on our site? Email us directly.
🤝
Partnerships Interested in collaborating? We'd love to hear from you.
☠
Get Notified of New Scam Reports
Subscribe to get an email the moment a new scam report or blog post goes live on BugBountyScam. Double opt-in, no spam, unsubscribe anytime.
☠
New Scam Reports Instant alert when a bug bounty program gets reported.
✎
Blog Posts Get notified when we publish new investigations.
🔒
Privacy First We never share your email. One-click unsubscribe in every message.
⌕ Program Lookup
Check if a bug bounty program has scam reports
☠ Wall of Shame
Programs with the most scam reports from the community
◈ Scam Analytics
⧖ Track Report
Enter your tracking ID to check submission status
✎ Blog
☆ Weekly Digest
Valid Bug Bounty Programs
Researcher-reported programs and experiences. Explore programs that researchers have interacted with — and read what actually happened — before you start hunting.
⚠ Researcher-submitted information. Program details, bounty ranges, response times and experiences are based on user submissions and may not be independently verified. Verify important details yourself before relying on them.
⌕
No programs match your filters.
Stay Updated
Get notified when new valid programs are approved.
Submit a Program
⚠ User-submitted bounty/response information may not be independently verified. Submissions are reviewed before publishing.
Share Your Experience
Tags (select any that apply)
Preview
Submission Terms
This must be your own experience.
Do not knowingly submit false information.
Do not publish passwords, API keys, tokens or credentials.
Do not publish confidential vulnerability information.
BugBountyScam may review, reject or remove submissions.
Submitted experiences may be displayed publicly.
☻ Chat
Join Community Chat
Enter name & email to chat
☠
Get Notified of New Scam Reports
Drop your email. We'll ping you the moment a new scam report or blog post goes live. No spam, unsubscribe anytime.