Geonode logo

Security at Geonode

We take the security of our platform and our users' data seriously. If you believe you've found a security vulnerability in any Geonode service, we want to hear from you.

How to report

Email us at security@geonode.com with:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce it
  • Any relevant screenshots, logs, or timestamps
  • Your name or handle. You're welcome to report anonymously, but note that to pay a bounty we need your real name and payment details. Anonymous reports are still reviewed and appreciated.

We'll acknowledge your report within 5 business days.

Scope

In scope:

  • geonode.com and all subdomains
  • repocket.com and all subdomains
  • The Geonode dashboard and customer API
  • Geonode proxy infrastructure

Out of scope:

  • Denial of service (DoS/DDoS) testing
  • Social engineering, phishing, or physical attacks
  • Third-party services we integrate with but do not operate
  • Automated scanner output without a demonstrated, reproducible vulnerability
  • Issues with no realistic security impact (e.g. missing security headers on static pages, clickjacking on pages with no sensitive actions)

Rules of engagement

  • Do not access, copy, download, or share data that isn't yours. If you encounter user or customer data, stop, report it, and delete anything you may have retrieved.
  • Do not degrade or disrupt our services.
  • Do not publicly disclose the issue until we've resolved it and agreed on disclosure together.
  • Only test against your own accounts.

Safe harbor

We will not pursue legal action against researchers who act in good faith, follow the rules above, and report vulnerabilities to us directly. We consider good-faith security research authorized under this policy.

Rewards

We pay bounties for valid reports at our discretion. To qualify for a reward, a finding must be of genuine security significance: it must demonstrate real, exploitable impact on Geonode systems or data. Bounties start at $200 USD. The final amount is determined case by case based on severity, impact, and report quality.

Reports that do not qualify for a bounty include duplicates of known issues, out-of-scope findings, theoretical issues without demonstrated impact, and automated scan results. Severity assessment and reward amounts are entirely at Geonode's discretion.

Thank you for helping keep Geonode and our users safe.