Work at MyFitnessPal Managed Bug Bounty? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.
MyFitnessPal is the #1 nutrition and food tracking app. We believe in community support and sharing techniques and successes! The security community is integral to helping keep our products and services safe for the users. This brief outlines steps for reporting vulnerabilities to us, what we expect, and what you can expect from us. We look forward to working with the security community to find security vulnerabilities in order to keep our business and customers safe. Program Rules Please read our entire policy page before you begin! IMPORTANT NOTE: COMMUNITY.MYFITNESSPAL.COM IS OUT OF SCOPE. The community forums are OUT OF SCOPE for this bug bounty program. Any posts, interactions, or other activities made in our community forums for the purpose of bug bounty testing are strictly prohibited. ANY TESTING OR REPORTS AGAINST COMMUNITY.MYFITNESSPAL.COM WILL RESULT IN PERMANENT REMOVAL FROM THIS PROGRAM. All authenticated activity on our platform must be conducted using a MyFitnessPal account linked to a @bugcrowdninja.com email address. Any activity as part of this engagement with MyFitnessPal linked to a non-Bugcrowd email address is strictly prohibited. Please provide detailed reports with reproducible steps and a PoC. If the report is not detailed enough with how the vulnerability can be leveraged, and how to reproduce the issue, the issue will not be eligible for a reward. When duplicates occur, we only award the first report that was received (provided that it can be fully reproduced). Submit one vulnerability per report, unless you need to chain vulnerabilities to illustrate impact. Multiple attack paths that target the same underlying vulnerability will be awarded one bounty. Avoid in any way damaging, disabling, overburdening, impairing, interrupting, degrading, or impeding the normal use of our services. Do not delete or destroy any data. Refrain from any activities that are prohibited, that violate applicable laws (including privacy laws), or that are harmful to the rights and interests of others. If you encounter user information or any other personally identifiable information (e.g., names, device identifiers, etc.) during your testing please stop immediately and notify us through Bugcrowd. This information is and shall remain confidential. Further guidance will be provided along with an appropriate bounty for your finding. Please refrain from automated scanning against the domain. Do not engage in extortion. Do not leave any system in a more vulnerable state than you found it. Do not brute force user credentials or test credentials from public data disclosures. Social engineering attacks (e.g. spear phishing) are prohibited. Only interact with MyFitnessPal accounts you own. Ratings/Rewards: For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority. Confidentiality By participating in this program you agree to keep any information you access or receive about MyFitnessPal (e.g., about MyFitnessPal systems, vulnerabilities, and the reports you submit) strictly confidential in accordance with the Standard Disclosure Terms and agree not to share such information with any third parties. Submission Requirements Summary of the bug Steps to reproduce Working proof of concept Impact is based on, but not limited to the following: How complex is the demonstrated exploit? How likely is it that this vulnerability could be exploited? Would an attacker economically benefit from exploitation? How many users can the exploit target at once? Is any private user data exposed? Is any confidential company data exposed?
Scope
5 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| *.myfitnesspal.com | website | ✓ bounty | not set |
| com.myfitnesspal.android | android | ✓ bounty | not set |
| iOS App | ios | ✓ bounty | not set |
| community-stage.myfitnesspal.com | website | out | not set |
| community.myfitnesspal.com | website | out | not set |