
Valve
External Program
Submit bugs directly to this organization
If you are a Steam user and have a security issue to report regarding your personal Steam account, please visit our support site https://help.steampowered.com/. This includes password problems, login issues, suspected fraud, and account abuse issues.
Please read the scope, bounty, and severity information carefully before submission. Our intent is to guide researcher attention to the most important areas and to reward the most actionable reports.
This program covers the Steam platform and current games developed and published by Valve. Please review the reward tables and scope descriptions below.
The Steam components in scope are:
For games developed and published by Valve, if the game is in scope as noted on the Scope section of the program, then we accept reports against the following components:
Game bugs, glitches and gameplay exploits are not in scope for the bug bounty program.
No authorization is given to test any other websites, servers, game titles, or mobile applications. No bounties will be given for any disclosures relating to any applications outside the scope of this program.
The following items are considered out-of-scope for all Valve offerings:
Additionally, the following items are out-of-scope for issues with Valve games and related components:
While researching, we'd like to ask you to refrain from:
Valve services make use of a number of open source and commercial packages. If you discover a vulnerability in a library or OS component, we strongly advise you to follow responsible disclosure procedures directly with the vendor. We will not pay bounties on undisclosed vulnerabilities in dependent components.
Patches to dependent libraries are generally rolled out by our internal change management systems. Reports will not be accepted if they refer to vulnerabilities that have been fixed upstream, and scheduled, but not yet applied to our software or production systems.
We welcome reports that identify Valve systems that have fallen out of date (indicating a problem with our update or change management procedures).
Many Valve websites use a cookie called 'sessionid.' This is used only as an anti CSRF token and is not used for user authentication. Please do not report attacks resulting in leaking the value of this cookie as account takeover vulnerabilities.
Please carefully review our guidelines for remote-code-execution exploits in Valve games.
We take unintentional leaking of unreleased applications on Steam seriously. If you are reporting an insecure object reference that can leak private details about an unreleased game (name, artwork, pricing, etc.), please make sure your report includes the relevant details for appid 3717370.
If the vulnerability only exists for applications with specific configuration conditions, please carefully describe the configuration as well as the insecure reference. Severity of this type of leak will depend on the type and complexity of the required configuration as well as the scope of any potential exposure.
Insecure object references for information that Steam marks Private are in scope. For non-personally-identifying player data, severity is generally capped at Low.
Remote code execution attacks can be complex to triage and assess. We place a premium on reports that can clearly demonstrate impact to users, and which are faster to technically validate.
Your report must meet the following requirements to be accepted:
For vulnerabilities in Valve games, the following are our highest priority for assessment, reward, and resolution:
Reports of the following types may have their severity, and therefore reward, reduced one or more levels from the initial CVSS score:
Reports of any of the following types may be accepted as in-scope, but will not be eligible for a reward:
When submitting potential vulnerabilities, we ask that you follow HackerOne's general guidelines for disclosure as well as the following additional guidelines. A submission that does not meet these requirements may not qualify for a bounty.
Valve embraces transparency in our security. We will generally disclose the details of vulnerabilities found, upon request. We will generally permit external discussions of them (such as blog posts), with our permission. We reserve the right to make exceptions to this policy at our discretion.
Please note that we will not consent to disclose reports if they have been marked out-of-scope or inapplicable, or where Valve has not taken a specific corrective action / mitigation.
You must comply with all applicable laws in connection with your participation in this program. You are also responsible for any applicable taxes associated with any reward you receive.
We may modify the terms of this program or terminate this program at any time. We won’t apply any changes we make to these program terms retroactively.
Valve will have the right to determine CVSS classification, report validity, duplications, exclusions and out-of-scope bugs in its sole discretion.
Reports received through other channels prior to being received through the bug bounty program are not eligible for bounty.