How to Dispute a Severity Rating Without Torching the Relationship
A researcher's guide to disputing a bug bounty severity rating: what new evidence actually reopens a verdict, what never works, and phrasing that keeps triagers on your side.
Your critical came back as a medium, and you are staring at the reply box deciding how hard to push. This is a negotiation you can win, and it is one you can lose in ways that cost you far more than the difference between a medium and a high. We triage for a living, which means we sit on the receiving end of these disputes constantly, and the ones that move a verdict share a shape, while the ones that get a report muted share a different one. Here is what actually works from the other side of the queue.
Read the program's severity framework before you argue
Before you type a word, find out what rules the program rates against. Most published programs link a severity framework in their policy: the Bugcrowd VRT, a CVSS calculator with documented context adjustments, or a custom internal matrix. Many programs also carve specific issues into fixed buckets: self-XSS is informational here, CSRF on this action is out of scope there, rate-limiting bugs cap at low.
Two things happen when you read this first. You find out whether the rating you are disputing is a judgement call or a policy the program applies to everyone, and those are completely different conversations. And you learn the vocabulary the program actually uses, so your argument lands in their terms instead of yours. Disputing a "low" on a bug the program's own matrix explicitly caps at low is not a dispute, it is asking them to break their published rules for you, and it reads exactly that way. If the framework genuinely misclassifies your bug, quote the framework back and show where your finding exceeds the bucket they put it in. That is an argument grounded in their own rules, and it is the strongest kind.
Argue impact with evidence, not CVSS arithmetic
The single most common losing move is arguing the vector string. "This is AV:N/AC:L/PR:N, that is a 9.8, not a 7.5." No triager has ever been moved by this, because every contested letter in that string is a claim about impact wearing a costume, and restating the costume louder does not make the claim true. The program already assigned the vector they think is right. Telling them to change a letter is telling them their judgement is wrong without giving them a reason to agree.
What moves a rating is a demonstrated impact they had not accounted for. Not asserted, demonstrated. Compare these two replies to a bug downgraded because the triager believed it required user interaction:
"This is clearly critical, the CVSS is 9.1, please re-rate. UI:N applies here."
versus
"The downgrade cites required user interaction. It does not require any: the payload fires on page load with no click. Video and the raw request are attached, sent from account atk@ against vic@ at 15:04 UTC, check your logs. That removes the UI:R you rated against."
The second one wins because it hands the triager a checkable fact that changes an input they actually used. You are not arguing the number, you are correcting the premise the number was built on, and you are doing their verification for them. That is the whole game.
What actually reopens a verdict
A closed or downgraded verdict reopens when you introduce information that was not in front of the triager when they rated it. In practice that is one of three things:
- A new exploitation path. The triager rated it assuming a precondition that you can now show is not required. "You rated this as needing an admin account. Here it is from a free-tier user, full repro attached." That is new, and it is decisive.
- A broader blast radius. You rated the read of one record. Now demonstrate the identifier is a sequential integer and the whole table enumerates, the multiplier that turns one record into a breach. The mechanism did not change, the scale did, and scale is severity.
- A demonstrated chain. The bug they called low is the first link in a chain to something serious. Do not describe the chain, execute it and attach the proof. "This open redirect on its own is low, agreed. Chained with the token in the
nextparameter it is a full account takeover, here is the working PoC." A demonstrated chain is the most powerful reopener there is, because it is a strictly new bug they have not seen.
The pattern across all three is that you are adding a fact, not adjusting an adjective. If your dispute contains new evidence, send it. If it contains only new emphasis, you do not have a dispute yet, you have a feeling.
What never works
Some moves do not just fail, they damage you. Triage teams keep a running calibration on every recurring submitter, the same way we describe in the researcher relations guide, and these are the moves that move you the wrong way on it.
Volume. Ten paragraphs restating the same impact does not outweigh one demonstrated fact. Long disputes that add no new information read as pressure, and pressure without evidence reads as inflation. The triager skims for the new fact, does not find it, and closes the thread.
Threats to disclose. "Re-rate this or I go public" converts you from researcher to adversary in one message. It torches the reputation that pays compounding dividends across every future report, and on most platforms it violates the disclosure terms you agreed to, which can void the bounty entirely. It is the single most expensive sentence you can type.
Platform escalation as a first move. Jumping straight to mediation or the platform's dispute process, before you have replied in the report thread with new evidence, tells everyone you would rather litigate than collaborate. Mediation exists and it works, but as a step you reach after the in-thread conversation genuinely stalls, not as your opening. Escalating first makes the triager defensive on every report you file afterward.
Arguing a policy verdict on technical merits. If the bug is "valid but out of scope" or "accepted risk," that is a business decision, not a reproduction dispute. Re-explaining the technical severity harder will not move it, because nobody disagrees with you about the technical severity. You are arguing with the wrong verdict.
Know when to take the L
Not every rating you disagree with is worth contesting, and part of playing this well is folding fast on the ones that are not. If the program applied its published framework correctly, if the verdict is a policy call rather than a technical one, or if you have already sent your best new evidence and it did not land, take the points and move on.
Taking the L cleanly is worth more than it looks. The triager who watched you accept a fair medium without a fight remembers it, and that memory pays out on the next genuinely ambiguous report, the one where they could go either way. Researchers who dispute everything get read defensively and argued against by default. Researchers who dispute selectively, only when they are holding new evidence, get read charitably and argued for internally. A reputation for calibrated disputes is a standing asset. Spending it on a bug that was rated correctly is a bad trade.
Phrasing that keeps triagers on your side
The tone that works is collaborative and evidence-forward. You are handing the triager a reason to change their mind and making it easy to verify, not demanding they admit an error. Some templates that keep the thread productive:
Opening a dispute with new evidence:
"Thanks for the review. I think the rating rests on [assumption], and I have new evidence that changes it: [demonstrated fact, with PoC attached]. Sent from [account] at [time] if you want to confirm against your logs. Happy to walk through it if useful."
Correcting a precondition:
"The rating cites [precondition]. I have reproduced it without that: [steps and proof]. That removes [the input they rated against]. Would you take another look with this in mind?"
Presenting a chain:
"Agreed the base issue is [low severity] on its own. It chains with [second issue] to reach [serious impact], full PoC attached. I think that changes the ceiling here, keen to hear your read."
Accepting the verdict:
"Understood, that is fair given [framework or policy]. Thanks for the detailed reasoning. I will keep it in mind for the next one."
Every one of these does the same two things: it foregrounds a checkable fact, and it leaves the triager room to agree without losing face. That combination is what gets verdicts reopened. The goal of a dispute is not to win the argument, it is to change the rating, and those are not always the same thing.
The researchers who get the most out of a dispute are the ones whose reports arrive clean enough that the dispute is a short conversation about one new fact, not a fight about a vague claim. TRIAGERS™ triages for programs that pay fast when reports are that clear, so a well-evidenced re-rate request tends to get read charitably and resolved quickly; if you want to know which programs we triage for, get in touch.