Security Acknowledgements
Researchers who reported a security issue to FactorCat and helped us fix it.
FactorCat is an MFA platform, so security is the product. The people listed here found something we had missed, told us privately, and gave us the time to fix it. We are grateful to all of them.
If you have found something, our responsible disclosure policy explains how to report it and what happens next.
-
Reported that a password reset did not sign out sessions that were already active, so a session started before the reset stayed signed in afterwards, and that password reset links stayed valid for longer than they needed to.
CWE-613: Insufficient Session Expiration
Completing a password reset now signs out every session on the account, and reset links expire substantially sooner. Fixed October 3, 2026.
How credit works
You tell us how you would like to appear and we use exactly that. It can be a name, a handle, a company, or Anonymous. You can include an optional link to a profile or site, or an email address you have chosen for this page.
Anonymous is the default. If you have not told us how you want to be credited, your entry is published as Anonymous with no link. We will not guess, and we will never publish the address you reported from unless you have specifically asked us to use it here.
The description of what you found, and of how we resolved it, is written by us. It is deliberately light on mechanism so that reading this page does not hand anyone a map of our systems.
Changing or removing your entry
You can add, change, or remove your details at any time, before or after your entry goes up. That includes adding a name or link later if you were originally credited as Anonymous, and asking to be removed entirely with no explanation needed.
Use our contact form and select "Security disclosure", or reply to the thread where you reported the issue.
Eligibility
An entry is created when a report is:
- The first report we received of a specific, previously unknown issue
- Reproducible, with enough detail for us to confirm it
- Filed in line with our responsible disclosure policy
We do not currently offer monetary bounties. As FactorCat grows, we intend to formalize a paid bug bounty program. For now, we offer our sincere thanks and public recognition.