Vulnerability Disclosure Program

Last Updated: 3 March 2025

0

Introduction

We run a skin marketplace. People trust us with inventories and balances, so we take security reports seriously. If you find something, tell us.

Over the years we have put a lot of safe guards in place to protect user funds. If you believe there is more gain by abusing the platform you could not be more than mistaken.

We welcome any reports.

Scope

Cs.deals and all subdomains

The CS.DEALS public API

Out of Scope:

Third-party services we don’t control (Steam, payment processors, Cloudflare, email providers). If the bug is theirs, report it to them. If the bug is on our end it may still be in scope.

Denial of service, rate-limit exhaustion, or anything that degrades service for real users

Social engineering of staff, users, or partners

Findings from automated scans with no impact

Findings related to public database/compromised accounts outside of cs.deals

Clickjacking on pages with no sensitive actions

Missing security headers, SPF/DMARC nitpicks, version disclosure, verbose errors. These count only if you chain them into real impact

1

Severity and Rewards

Severity

Definition

Examples

Reward (USD)

Critical

Loss of user funds or items at scale, or full infrastructure compromise.

Item duplication · Balance manipulation · Draining another user’s funds or items · Trade bot takeover · RCE · Auth bypass · User database leak

$6,000 – $20,000

High

Single-account compromise or significant financial impact with preconditions.

Account takeover · Stored XSS · Fee or price bypass · IDOR exposing balances or emails · SSRF to internal services · Admin privilege escalation

$1,500 – $6,000

Medium

Bounded data exposure or logic flaws

Reflected XSS · CSRF on listings or pricing · Rate-limit bypass · IDOR on non-sensitive data · Leaked bot API keys · Minor financial logic flaws

$300 – $1,500

Low

Negligible direct impact

Info disclosure with no exploit path · Theoretical missing controls · UI redress on non-sensitive pages · Stack traces in errors

$0 – $300 or credit

2

How To Report

Step 1

Open Support Ticket for faster response

Step 2

Add Explanation of what the bug is

Step 3

Add proof of concept on how to recreate it

Step 4

Add Your CS DEALS account used to find and create the vulnerability

Step 5

Media can be shared as videos uploaded on streaming website.

Support is not permitted to download files

For email communication email the above mentioned details to:

security@cs.deals

with topic “URGENT - SECURITY DISCLOSURE”

If the mentioned details are missing reports may take longer to validate.

3

What Happens Next

Step

Our response time at maximum. Often times far faster.

Acknowledge Receipt

Within 2 business days

Severity assigned

Within 3 business days

Fix timeline communicated

Within 10 business days

4

Rewards

Rewards are paid in crypto (USDT/USDC) or by bank transfer. Amounts within a band depend on exploitability, quality of report, and whether you included a working PoC.

Exceptional reports can be paid above the band.


We cannot stress enough the upside that comes with reporting rather than receiving far less by using a vulnerability for personal gain.