— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Airtable.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"allows_bounty_splitting": true,
"average_time_to_bounty_awarded": 160,
"average_time_to_first_program_response": null,
"average_time_to_report_resolved": null,
"handle": "airtable",
"id": 0,
"managed_program": true,
"name": "Airtable",
"offers_bounties": true,
"offers_swag": false,
"response_efficiency_percentage": 72,
"submission_state": "open",
"url": "https://hackerone.com/airtable",
"website": "https://staging.airtable.com/",
"targets": {
"in_scope": [
{
"asset_identifier": "*.staging-airtableblocks.com",
"asset_type": "WILDCARD",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "IMPORTANT: this domain is NOT eligible for stored XSS via building custom apps/blocks functionality.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "*.staging.airtable.com",
"asset_type": "WILDCARD",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "airtable.js SDK (https://www.npmjs.com/package/airtable)",
"asset_type": "SOURCE_CODE",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "- Install `airtable.js` via `npm install airtable`\n- Visit https://staging.airtable.com/account and generate an API key\n- Create a new Javascript file and add the following lines:\n\n```javascript\nconst Airtable = require('airtable');\nconst airtable = new Airtable({\n apiKey: 'PUT YOUR API KEY HERE',\n endpointUrl: 'https://api-staging.airtable.com', // IMPORTANT: you MUST set the endpointUrl attribute to this URL, or else you will be testing on airtable.com, which is out of scope\n});\n```\n\nSee https://staging.airtable.com/api for instructions on how to use the API, as well as [the source code on Github](https://github.com/airtable/airtable.js)\n\nPlease note that reports about outdated/vulnerable dependencies flagged by `npm audit` or `yarn audit` are **out of scope**. Vulnerabilities discovered via manual code audits are acceptable.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "api-staging.airtable.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Go to https://staging.airtable.com/account to generate an API key. See https://staging.airtable.com/api for API documentation per base.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "https://www.npmjs.com/package/@airtable/mcp-cli",
"asset_type": "SOURCE_CODE",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Source code for our MCP CLI.\n\nVulnerabilities assuming a malicious MCP server must be paired with a demonstrated MCP exploit that provides a full exploit chain in order to be considered.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "mcp.staging.airtable.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Use the official Airtable MCP CLI (https://www.npmjs.com/package/@airtable/mcp-cli) to interact with the MCP server. \n\nMCP CLI code is also in scope, but vulnerabilities assuming a malicious MCP server must be paired with a demonstrated MCP exploit that provides a full exploit chain.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "staging.airtable.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": null,
"max_severity": "critical"
}
],
"out_of_scope": [
{
"asset_identifier": "Airtable Windows app",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "The Airtable Windows app is available for download at: https://staging.airtable.com/downloads",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "Airtable macOS app",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "The Airtable macOS app is available for download at: https://staging.airtable.com/downloads",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "airtable.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This is production environment. All testing should be performed against staging.airtable.com.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "blog.airtable.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "com.FormaGrid.Hyperbase",
"asset_type": "APPLE_STORE_APP_ID",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Airtable's iOS is not in-scope for bounties.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "com.formagrid.airtable",
"asset_type": "GOOGLE_PLAY_APP_ID",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "community.airtable.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "dl.airtable.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "dl.getforma.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "guide.airtable.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "support.airtable.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": null,
"max_severity": "none"
}
]
}
}api-staging.airtable.com· criticalairtable.js SDK (https://www.npmjs.com/package/airtable)· criticalwww.npmjs.com/package/@airtable/mcp-cli· criticalAirtable Windows appAirtable macOS appcom.formagrid.airtable