Feed
Bounty Rolling

Microsoft Open Source Bounty Program

Microsoft pays $750 to $15,000 USD for qualifying security vulnerabilities in open source projects such as Visual Studio Code, TypeScript, PowerShell 7 and the Azure SDKs. Submissions are accepted on a rolling basis.

The Microsoft Open Source Bounty Program rewards security researchers who find vulnerabilities in selected Microsoft open source projects. Qualified submissions are eligible for bounty awards from $750 to $15,000 USD. Microsoft says higher amounts are possible at its discretion, depending on severity, impact and the quality of the submission.

Projects in scope include the Azure SDKs for .NET, Python, JavaScript, Java, Go and Rust, FluentUI, PowerShell 7, TypeScript, Visual Studio Code, monaco editor, MsQuic and the Microsoft Agent Framework. The program page lists exclusions, for example semantic kernel and autogen are not covered.

To qualify, a vulnerability must be of Critical or Important severity. It must be reproducible on the most recent actively maintained branch, present in the open source library by default or visible in a Microsoft service, and not previously reported to Microsoft.

Reports are submitted through the MSRC Researcher Portal, which is linked from the program page. There is no deadline. The program page was last revised on June 22, 2026.

Microsoft lists the kinds of issues it looks for: code injection, deserialization flaws, authentication issues, server side request forgery, access control failures, cross site scripting and supply chain vulnerabilities with a direct security impact on customers.

Source · microsoft.com/en-us/msrc/opensourcebountyprogram Published 22 June 2026 · Added here 6 September 2026