Early access: this site has moved to bugrater.com.
NR Unrated
CodeAI
CodeAI Bugcrowd
3 more reviews needed for a grade
Write a review Claim this company profile

Work at CodeAI? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Reviews

0 published

No reviews yet.

Be the first to review

Program profile Bugcrowd · imported

Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 20 Sep 2026.

Program temporarily paused Effective August 1 at 12:00am Pacific Time, the CodeAI bug bounty program is temporarily paused while we work through our current submission and remediation backlog and reassess how the program should operate. The engagement is not accepting new bounty submissions during the pause. Reports submitted before the pause took effect will continue to be reviewed under the program terms that applied when they were submitted. We do not yet have a date for resuming the program. We will post an update if and when bounty submissions reopen. Urgent security concerns may still be reported through security@code.org, but reports submitted while the program is paused are not eligible for monetary rewards. NOTICE: Backlog reports submitted before the pause will be reviewed for technical validity; due to a funding pause, they are not eligible for monetary rewards. PAUSED PROGRAM BRIEF: Welcome to the CodeAI Bug Bounty Program At CodeAI®, our mission is to give every student access to a world-class computer science education. We appreciate your time and expertise in helping us safeguard that mission. By reporting security issues here, you’re supporting millions of learners—and ensuring student data stays protected. Basic Rules & Best Practices Keep Findings Confidential: Please disclose vulnerabilities only through this platform. Please do not release without our consent. Be Considerate of the Environment: Use your @bugcrowdninja.com email for test accounts, and steer clear of any testing that might affect legitimate user data or other researchers’ work. For more info regarding @bugcrowdninja email addresses, see here. Respect Rate Limits: We appreciate your thoroughness, but please avoid overwhelming our systems or performing Denial-of-Service attacks—our test environment is modest. Stay Within Scope: If you discover something on a domain not explicitly listed, we still welcome the report, but it may not qualify for a bounty if it’s marked out-of-scope. Open Source & Accessibility Our application code is largely open source, so you can dig into our GitHub repository for deeper insight. We also host a publicly accessible target environment, which means you’re free to sign up as different role types (student, teacher, admin, etc.) using your bugcrowdninja.com address. Just remember: no real PII beyond what’s necessary for test accounts, please. CodeAI User Types Students – Minimal PII (hashed email, first name), can join teacher sections and create/share projects. Teachers – Self-chosen by the user at account creation; manage sections, assign work, and set simplified logins for kids. Teachers have limited access to control the log in options for students that have joined their class (section) Verified Teacher – A teacher marked “verified” by an admin; can bypass throttling; access content not generally available Facilitators/Regional Partners – Oversee teacher PD courses but don’t handle student credentials. Admins – CodeAI staff with elevated privileges (must have @code.org email); can assume user identities for support. To minimize sensitive data, we don’t store last names or emails for students. Account Creation & Login Methods Email & Password – Straightforward sign-in (students’ emails are hashed). Single Sign-On (SSO/OAuth) – Google, Microsoft, Facebook, Clever, etc.; accounts can link multiple providers. Teacher-Created Accounts – Teachers provide a 6-letter section code (no personal email required). Simple Logins – Picture choice or two-word phrase for younger students. Federation (External Tools) – Automatic creation/login via Google Classroom, Schoology, LTI, etc. We recommend you make separate “teacher” and “student” logins using [username]+teacher@bugcrowdninja.com and [username]+student@bugcrowdninja.com Things that Users Own Student Coding Projects We offer various “Labs” tailored for different programming experiences. Students can create projects using labs like these: Block-Based Labs (Sprite Lab, Flappy, Minecraft, Frozen, Dance Party): Intro to coding via drag-and-drop blocks. App Lab and Game Lab: More advanced, allowing JavaScript coding and game creation. Web Lab: Lets students build and host HTML/CSS projects. 🎉 Python Lab: Our new lab type, executing Python in the web browser. Java Lab, AI Lab, and Others: Specialized experiences for Java, AI experiments, and a variety of legacy labs. Students should be the only ones allowed to edit their project. However, most labs are automatically shared, if someone knows the link. Our share functions only make it easier to share the existing public link. Visitors see a read-only version of the project and can “remix”. Curriculum Curriculum can be accessed in one of two ways: Teachers assign curriculum to students (and when the student logs in, they are immediately taken there) Students can directly browse the Course Catalog Curriculum “levels” are units of educational content that behave similarly to Projects. They save the student’s work, but these do not have the sharing functions that projects do. There are various other variations in the curriculum level experience, to instruct and measure progress

Submissions
Open
Scope entries
4 Bugcrowd’s count

Scope

4 assets
AssetTypeEligibilityMax severity
adhoc-bugcrowd-studio.cdn-code.org website submit only not set
adhoc-bugcrowd.cdn-code.org website submit only not set
advocacy.code.org website out not set
hourofcode.com website out not set