# SUBMIT Handoff - 2026-02-12 Trigger: SUBMIT All findings currently in `draft` status are ready for human platform submission. ## Draft Reports | finding_id | program | platform | vuln_type | severity | confidence | report_path | |------------|-----------|----------|-----------------------------------|----------|------------|--------------------------------------------------------------------------| | 6 | LibreChat | huntr | Account Takeover / Password Reset | critical | high | reports/LibreChat-PasswordResetLinkLeak-2026-02-12.md | | 4 | LibreChat | huntr | IDOR / Broken Access Control | high | high | /Users/sebas/Code/bug-bounty/reports/LibreChat-IDOR-2026-02-12.md | | 12 | BentoML | huntr | Deserialization / RCE | high | high | reports/BentoML-PickleRCE-2026-02-12.md | | 14 | RAGFlow | huntr | Auth Bypass | high | high | /Users/sebas/Code/bug-bounty/reports/RAGFlow-AuthBypass-2026-02-12.md | | 16 | RAGFlow | huntr | Path Traversal | high | high | /Users/sebas/Code/bug-bounty/reports/RAGFlow-PathTraversal-2026-02-12.md | | 3 | MLflow | huntr | path-traversal | medium | medium | /Users/sebas/Code/bug-bounty/reports/MLflow-FileRead-2026-02-12.md | | 19 | RAGFlow | huntr | Auth Bypass | medium | medium | reports/RAGFlow-UnauthImageAccess-2026-02-12.md | ## Notes - Submit each report to its platform using the corresponding report file. - After submission, update each finding to `submitted` and set `submission_url` in `data/findings.db`.