Please do not report security vulnerabilities through public GitHub issues.
Report suspected vulnerabilities through Plaid's responsible disclosure process:
- Vulnerability disclosure: https://hackerone.com/plaid
Include as much detail as possible, including the affected Flutter SDK version, platform, native SDK version, reproduction steps, logs, and potential impact. Do not include Plaid secrets, access tokens, link tokens, public tokens, personally identifiable information, or production customer data.
Security fixes are prioritized for the latest published major version of the Flutter SDK. Upgrade to the latest release before reporting an issue that may already be fixed.
Plaid will review reports submitted through the responsible disclosure process and communicate through that private channel. Response and remediation timing depend on severity, impact, and complexity. Please keep vulnerability details confidential until Plaid has investigated the report and coordinated any required disclosure.