● SEC / OPS — Responsible Disclosure

TeleLive Bug Bounty

Found a bug? Nice work — open a ticket. Critical security issue? Call us and say code 4.

telelivee.ir + API
Responsible disclosure
Code 4 = security

Submit report (ticket)

Technical bugs, UI, account, or content — use the form below.

Clear reports with PoC and repro steps get reviewed faster. Thanks for helping secure TeleLive.

report.sh — session_active
No file selected

Scope

telelivee.ir

Main website, dashboard, live streaming, chat, payments, and accounts.

API & realtime services

Official /api/* endpoints and TeleLive services on this domain.

WebSocket / Socket.IO

Live chat and realtime via telesocket.liara.run (Socket.IO).

Out of scope

DoS, phishing, social engineering, automated scans without PoC, third-party, unofficial subdomains.

Severity guide

Critical

RCE, mass sensitive data exposure, SQL/command injection with high impact.

High

Account takeover, sensitive IDOR, high-impact SSRF, stored XSS with privilege escalation.

Medium

State-changing CSRF, reflected XSS, limited information disclosure.

Low

Minor misconfigurations without direct exploit, GET open redirects.

Bug bounty rewards

After a valid fix, the team may grant one of the rewards below. The Bug Reporter badge and achievement unlock automatically on Resolve.

Critical — up to 500 Tele or 1 month Ultra
High — up to 250 Tele or a Tier-1 gift sub
Medium — up to 100 Tele
Low — Bug Reporter badge & achievement

Rewards are granted after manual review; duplicates and out-of-scope reports are not eligible.

Bug hunters

Thanks to everyone who reported bugs and helped make TeleLive better.

Rules & limits

  • 01Do not download, modify, or delete user data.
  • 02No DoS/DDoS, brute force, or spam.
  • 03Do not publicly disclose before we fix the issue.
  • 04One vulnerability per report; duplicates are merged.
  • 05Test only on your own assets or with the channel owner’s consent.
  • 06Automated scanner output without attack scenario and PoC is out of scope.