Blog icon

About our security vulnerability disclosure policy

Protecting CSIRO's systems, information and research is important to us. We maintain security controls designed to protect our digital services, but security vulnerabilities may still be discovered.

CSIRO welcomes responsible reports from security researchers, customers, partners and members of the public who believe they have identified a security vulnerability affecting a CSIRO system, service or product.

If you believe you have found a security vulnerability, please report it to us as soon as possible so we can investigate and, where necessary, take action to address it.

CSIRO does not currently operate a bug bounty program and does not offer financial rewards for vulnerability reports.

What you can report

You can report suspected security vulnerabilities affecting publicly accessible CSIRO systems, services or applications.

This may include:

  • vulnerabilities in websites or web applications
  • authentication or access control weaknesses
  • exposure of sensitive information
  • security configuration issues
  • cross-site scripting
  • injection vulnerabilities
  • server-side request forgery
  • vulnerabilities that may allow unauthorised access to CSIRO systems or information
  • vulnerabilities in CSIRO-developed software or publicly available digital services.

If you are uncertain whether an issue is a security vulnerability, you can still report it.

How to report a vulnerability

Send your report to: VulnerabilityDisclosure@csiro.au

Include as much information as possible to help us reproduce and assess the issue.

Where possible, provide:

  • the affected website, system, application or service
  • the URL, hostname or IP address involved
  • a description of the vulnerability
  • the date and time you identified it
  • the steps required to reproduce the issue
  • screenshots, request and response data, or other supporting evidence
  • any proof-of-concept code, provided it does not contain malicious functionality
  • the potential security impact
  • your name and contact details if you would like us to contact you.

Please do not include sensitive information that is not required to demonstrate the vulnerability.

Responsible security research

When investigating a potential vulnerability, we ask that you act responsibly and minimise any risk to CSIRO, our people, research partners, customers or systems.

You should:

  • only conduct testing necessary to demonstrate the existence of the vulnerability
  • stop testing if you gain access to information that you are not authorised to access
  • minimise access to, collection of, or interaction with CSIRO information
  • avoid changing or deleting information
  • avoid disrupting CSIRO services or research activities
  • report the vulnerability to CSIRO promptly
  • give CSIRO reasonable time to investigate and address the issue before publicly disclosing it
  • securely delete any CSIRO information obtained during your research when it is no longer required.

Activities that are not permitted

This policy does not authorise you to:

  • deliberately access information beyond what is necessary to demonstrate a vulnerability
  • download, copy, modify or delete CSIRO information
  • access another person's account
  • attempt to obtain passwords, credentials or authentication tokens belonging to another person
  • use social engineering, phishing or physical intrusion
  • conduct denial-of-service or resource exhaustion testing
  • deploy malware
  • establish persistence within a CSIRO system
  • attempt to move laterally between systems
  • exploit a vulnerability for purposes other than demonstrating and reporting it
  • compromise third-party systems or services used by CSIRO
  • interfere with CSIRO research, scientific instruments, operational technology or laboratory systems
  • carry out testing that could affect the

About our security vulnerability disclosure policy

Protecting CSIRO's systems, information and research is important to us. We maintain security controls designed to protect our digital services, but security vulnerabilities may still be discovered.

CSIRO welcomes responsible reports from security researchers, customers, partners and members of the public who believe they have identified a security vulnerability affecting a CSIRO system, service or product.

If you believe you have found a security vulnerability, please report it to us as soon as possible so we can investigate and, where necessary, take action to address it.

CSIRO does not currently operate a bug bounty program and does not offer financial rewards for vulnerability reports.

What you can report

You can report suspected security vulnerabilities affecting publicly accessible CSIRO systems, services or applications.

This may include:

  • vulnerabilities in websites or web applications
  • authentication or access control weaknesses
  • exposure of sensitive information
  • security configuration issues
  • cross-site scripting
  • injection vulnerabilities
  • server-side request forgery
  • vulnerabilities that may allow unauthorised access to CSIRO systems or information
  • vulnerabilities in CSIRO-developed software or publicly available digital services.

If you are uncertain whether an issue is a security vulnerability, you can still report it.

How to report a vulnerability

Send your report to: VulnerabilityDisclosure@csiro.au

Include as much information as possible to help us reproduce and assess the issue.

Where possible, provide:

  • the affected website, system, application or service
  • the URL, hostname or IP address involved
  • a description of the vulnerability
  • the date and time you identified it
  • the steps required to reproduce the issue
  • screenshots, request and response data, or other supporting evidence
  • any proof-of-concept code, provided it does not contain malicious functionality
  • the potential security impact
  • your name and contact details if you would like us to contact you.

Please do not include sensitive information that is not required to demonstrate the vulnerability.

Responsible security research

When investigating a potential vulnerability, we ask that you act responsibly and minimise any risk to CSIRO, our people, research partners, customers or systems.

You should:

  • only conduct testing necessary to demonstrate the existence of the vulnerability
  • stop testing if you gain access to information that you are not authorised to access
  • minimise access to, collection of, or interaction with CSIRO information
  • avoid changing or deleting information
  • avoid disrupting CSIRO services or research activities
  • report the vulnerability to CSIRO promptly
  • give CSIRO reasonable time to investigate and address the issue before publicly disclosing it
  • securely delete any CSIRO information obtained during your research when it is no longer required.

Activities that are not permitted

This policy does not authorise you to:

  • deliberately access information beyond what is necessary to demonstrate a vulnerability
  • download, copy, modify or delete CSIRO information
  • access another person's account
  • attempt to obtain passwords, credentials or authentication tokens belonging to another person
  • use social engineering, phishing or physical intrusion
  • conduct denial-of-service or resource exhaustion testing
  • deploy malware
  • establish persistence within a CSIRO system
  • attempt to move laterally between systems
  • exploit a vulnerability for purposes other than demonstrating and reporting it
  • compromise third-party systems or services used by CSIRO
  • interfere with CSIRO research, scientific instruments, operational technology or laboratory systems
  • carry out testing that could affect the

Report a system security vulnerability

You can report suspected security vulnerabilities affecting publicly accessible CSIRO systems, services or applications.

Email us now