Scam Alert: huntr.com — Huntr scoped the Kubeflow engagement to a repo with no code, closed 14 critical/high reports as NA, then banned the account
Company / Program: huntr.com
Platform: Other · Severity: critical · Scam type: no-payout
Published:
Reported by: OmhCrl
The Huntr engagement for Kubeflow listed kubeflow/kubeflow as the repository in scope. That repository contains no application code. Its own README states that "This repository serves primarily as a gateway to Kubeflow subprojects and shared project metadata. Kubeflow development happens in the individual subproject repositories."
Since there was nothing to analyse in the listed repository, I submitted my findings against the subproject repositories named in the official Kubeflow documentation. These are the components Kubeflow is actually built from, not forks, mirrors, or unrelated projects.
I submitted 14 findings, all rated critical or high. One was initially accepted with a confirmed bounty, then reversed. The stated reason was that the report targeted a subproject rather than kubeflow/kubeflow. The remaining reports were closed as not applicable on the same grounds.
Both readings of the scope cannot be correct at the same time. If only kubeflow/kubeflow is in scope, hunters are being asked to find vulnerabilities in a repository that holds a README and nothing else. If the code lives in the subprojects, which is what the repository itself says, the reports were in scope and should have been judged on technical merit.
My account was banned shortly after I raised this. I was given no explanation and no chance to respond before the ban was applied. The unpaid bounties come to over 10,000 USD by my calculation.
I have contacted Huntr support directly with the same information and have not received a resolution.