> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.6mm.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.6mm.com/_mcp/server.

# 回報安全漏洞或事件

安全報告應包含足夠的技術背景，讓 6MM 團隊能評估影響並安全地重現問題。

<h2 id="reportable-issues">
  可重裝問題
</h2>

* API、 SDK、webhook、認證或交易進入流程中的漏洞。
* 可疑的生產行為，可能影響交易誠信或使用者安全。
* 憑證外洩或疑似未經授權存取。
* 可能影響系統穩定性的濫用模式。

<h2 id="include-in-the-report">
  納入報告
</h2>

* 受影響的環境與端點。
* 時間範圍與再生步驟。
* 日誌、請求 ID、webhook 事件 ID 或截圖。
* 該議題目前是否仍在運作。

<h2 id="safe-reporting-guidelines">
  安全舉報指引
</h2>

* 不公開未修復的漏洞。
* 不得存取、下載、更改或保留超出證明問題所需的資料。
* 不進行阻斷服務、破壞性、社會工程或資金流動測試。
* 使用測試帳號及最小的安全概念驗證。
* 從附件中移除密碼、 API 秘密、存取權杖、私鑰及無關個人資料。

<h2 id="suggested-report-format">
  建議報告格式
</h2>

```text
Title:
Affected component and environment:
First observed time (UTC):
Issue status:
Technical description:
Reproduction steps:
Expected security behavior:
Observed behavior:
Potential impact:
Sanitized evidence:
Researcher or partner contact:
```

<h2 id="security-contact">
  安全聯絡
</h2>

私下將漏洞及緊急安全報告寄送至：

\[[security@6mm.com](mailto:security@6mm.com)]（Mailto：[security@6mm.com](mailto:security@6mm.com)）

一般整合問題應使用 \[支援請求模板]（/resources/support-request-template）。研究者也應檢視\[漏洞懸賞計畫]（/security-compliance/bug-bounty-program）的範圍及負責任揭露的期望。
<h2 id="localized-page-links">相關頁面</h2>

* [技術支援申請範本](/zh-TW/resources/support-request-template)
* [漏洞懸賞計畫](/zh-TW/security-compliance/bug-bounty-program)