Helio
Created by admin · 1 week ago
Description
Customer Data Platform. A single typed GraphQL API over contacts, companies, segments, events and campaigns. The schema is rich, the docs are public and the dashboard looks trustworthy - which is exactly why the authorization model underneath it deserves a closer look.
Scope
helio.thebugbountyroom.com - the GraphQL endpoint at /graphql and every query and mutation it exposes. Assume the schema is documented and that object ids are guessable. Focus on what the server checks about *which object* and *whose* object it is, and on what a field returns once the parent resolved.
Out of Scope
Denial of service, resource exhaustion, credential stuffing against platform logins, other subdomains, and the /app dashboard UI.
Recent Submissions
Submit ReportNo reports yet. Be the first to submit!