If you discover a security vulnerability in QRIS Bridge, please report it privately.
Do not open a public GitHub issue. Instead, send an email to:
We will acknowledge receipt within 48 hours and provide an estimated timeline for a fix.
The following are in scope:
- Server-side vulnerabilities that could leak merchant data or secrets
- Authentication or authorisation bypass in device registration or WebSocket access
- Webhook signature bypass or HMAC weaknesses
- Duplicate detection bypass
The following are out of scope:
- Compromised Android devices (malware, rooted devices)
- Social engineering attacks
- OEM battery optimization killing foreground service
- We will notify you once the vulnerability is confirmed.
- A fix will be developed and tested privately.
- Once the fix is released, we will publish an advisory with credit to the reporter (unless anonymity is requested).
- We ask for a 90-day disclosure window from the date of the first response.
We ask:
- Report privately, do not publish before patch
- Provide sufficient detail for reproduction
- Do not exploit the vulnerability