Security Researchers
If you believe you have found a security vulnerability in one of our websites, we welcome and greatly appreciate you reporting it to Mercado Libre.
Last update 07/12/2023
Security
Functional bugs like the following are outside the scope of our vulnerability disclosure program:
- Platform crashes or outages.
- Non-functioning buttons or links.
- Unexpected errors.
- Minor user interface inconsistencies or visual glitches.
- Others
We encourage individuals to submit reports regarding potential security vulnerabilities, such as weaknesses, flaws, or breaches that could compromise the security of our customers and their data.
Security Issues applicable to our vulnerability disclosure program:
- Identification of a critical vulnerability that allows unauthorized access to sensitive data.
- Modification of information belonging to other users.
- Vulnerabilities listed in OWASP Top Ten.
- Discovery of a flaw that enables remote code execution on our systems.
- And other similar issues that directly impact the integrity, confidentiality, or availability of our systems.
Your contributions help us ensure the strength and reliability of our ecosystem.
Thank you for your cooperation in keeping our systems secure.
|