Skip to content

Subdomains pointing to vercel.com are vulnerable #183

@AliSalman-et-al

Description

@AliSalman-et-al

Service name

Vercel

Proof

Successful subdomain takeover on a harvard.edu subdomain (screenshot).
proof-vercel

Documentation

  • Create a new repository on Github and upload an index.html
  • Visit https://vercel.com/ and sign up using your Github account
  • Create a new project and point it to the previously created Github repository
  • Open the "Domains" tab on Vercel and add the vulnerable domain
  • Boom! Exploited!

Metadata

Metadata

Assignees

No one assigned

    Labels

    edge caseAn edge case was discovered where it is possible to hijack a subdomain on this service.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions