Please do not report security vulnerabilities through public GitHub issues.
Report suspected vulnerabilities through Plaid's responsible disclosure process:
- Security page: https://plaid.com/security/
- Vulnerability disclosure: https://plaid.com/security/disclosure/
Include as much detail as possible, including affected SDK version, platform, reproduction steps, logs, and impact. Do not include Plaid secrets, access tokens, link tokens, personally identifiable information, or production customer data.
Security fixes are prioritized for the latest published major version of the React Native SDK. Upgrade to the latest release before reporting issues that may already be fixed.