Work at Cloudinary? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.
Introduction Cloudinary, a SaaS/API provider that streamlines a website's entire image management pipeline, is the market leader in providing a comprehensive cloud-based image and video management platform. Using Cloudinary you can easily move all your website’s images and other assets to the cloud. Automatically perform smart image resizing, cropping, merging, overlay, watermark, apply effects, rotations and perform format conversions. All this without installing any complex software. Simply put, if you have images in your web or mobile app, let Cloudinary manage them for you. Cloudinary offers comprehensive APIs and administration capabilities and is easy to integrate with any web application. To simplify integration further we also have client libraries for Ruby on Rails, Python/Django, PHP, .NET, Node.js and more. In addition, alternative integration methods allow non-developers, bloggers and website administrators to enjoy Cloudinary with nearly zero code changes. We truly believe that this program plays a key role in protecting our customers and their data. We appreciate all security submissions and strive to respond expediently. We are particularly interested and will consider extraordinary submissions for: Issues that result in a full compromise of a Production system (e.g, RCE, obtaining a shell back from our network) Business logic bypasses resulting in a significant impact Major operational failure (excluding Denial of Service related submissions) Please read carefully below for submission guidelines and targets
Scope
7 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| dimensions.cloudinary.com | website | ✓ bounty | not set |
| https://api.cloudinary.com | api | ✓ bounty | not set |
| https://cloudinary.com/console | website | ✓ bounty | not set |
| https://res.cloudinary.com | api | ✓ bounty | not set |
| mediaflows.cloudinary.com | website | ✓ bounty | not set |
Show all 7 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| https://support.cloudinary.com | website | out | not set |
| wiki.cloudinary.com | website | out | not set |