06 / Articles 4 articles

Articles

We only write up a vulnerability after the patch ships — the reproduction steps, the attempts that failed, and why we looked there in the first place.

chwrld 4 min read

Write-up format

The house format for research notes: every frontmatter field and what belongs in it, how to use code blocks, images and tables, and the redaction checklist that runs before anything is published.

chwrld 4 min read

Responsible disclosure policy

How TEAM N1TRO reports the vulnerabilities it finds and when it publishes them: the disclosure window, the exceptions, and what vendors and reporters can each expect from us.

Awaiting full disclosure

Findings whose fix has shipped, with the write-up still in preparation. Vendor, class, identifiers and bounty are listed; only the details, reproduction steps included, are members-only.

Findings whose fix has shipped, with the write-up still in preparation. Vendor, class, identifiers and bounty are listed; only the details, reproduction steps included, are members-only.
VendorClassRefsBountyStatus
Authentication bypassCVE-2026-31337$10,000patchedSep 2026
IDOR—$5,000patchedSep 2026

Members only

The fix has shipped, but the write-up is still team-only. Vendor, class, identifiers and bounty are all in the table above — only the details, reproduction steps included, are members-only.