BBLABSBBLABS
LaboratoriosAprender desde 0FuncionesPreciosTestimoniosDetrás de BBLABS
  1. Inicio
  2. Labs
  3. self_svg_XSS — Self-XSS → Bot-Assisted ATO via SVG upload
Media15 min

self_svg_XSS — Self-XSS → Bot-Assisted ATO via SVG upload

Por @gorka

Chain an SVG upload, a `blob:` URL, a chat invite and a headless admin helper bot to turn a Self-XSS into full admin account takeover

$750

Es lo que una empresa pagó por este fallo en HackerOne. Aquí lo tienes reconstruido para que lo encuentres tú.

1.3K visitas28 completadosActualizado sept 2026
Iniciar sesión para empezar

Aprende a encontrar este bug

Este bug pagó $750 en HackerOne.

Crea tu cuenta y practica bugs reales que se pagaron. Descarga el entorno, encuéntralo y aprende la técnica exacta — tu camino a tu primer bounty.

650

hunters entrenando

50

labs de hackeos reales

380

completaciones

$12.000

pagados por estos bugs

40 flags capturadas esta semana
Crear cuenta
Ya tengo cuenta

Acceso a todos los labs · sin permanencia · cancela cuando quieras

Hackers que lo han resuelto· 8

elc0ket1
@elc0ketHace 5 días
r00thor2
@r00thorHace 8 días
emperador3
@emperadorHace 8 días
cibx
@cibxHace 9 días
bizedtv
@bizedtvHace 13 días
<d4r1c4r0>
@<d4r1c4r0>Hace 24 días
lxbx
@lxbxago 2026
mateoalahuacbam
@mateoalahuacbamago 2026

Objetivos

1
Identify how file previews are rendered (→ `window.open(URL.createObjectURL(blob))`)
2
Realize that SVGs opened as blob-URL documents execute `<script>`
3
Confirm that JWT auth tokens are kept in `localStorage['nc_token']`
4
Notice the in-app chat-invite feature and the admin helper bot
5
Craft an SVG that exfiltrates the admin JWT to `/api/exfil/<your id>`
6
Invite the admin, wait for the bot, harvest the token, hit `/api/admin`

Información

Plataforma
HackerOne
Dificultad
Media
Duración
15 min
Bounty
$750
Completados
28
Creador
gorka@gorka
Colaboradores
antoniorivera@antoniorivera
Actualizado
sept 2026

Descarga el entorno

Reprodúcelo y encuentra el bug tú mismo

Crear cuenta

Herramientas

Burp Suite

Prerequisitos

  • Python 3 with `requests` (for `exploit.py`)
  • Familiarity with browsers'

Tags

XSS

Logro que recibirás

Cuando resuelvas este lab desbloqueas este logro compartible

Cuando resuelvas este lab desbloqueas este logro compartible

Writeups de la comunidad

Gratis · sin cuenta

La checklist que repaso en cada objetivo nuevo

47 comprobaciones ordenadas por coste: primero lo que te puede meter en un lío, luego lo barato, y al final lo caro — que es donde están los bounties grandes. Te la mando al correo ahora mismo.

Te das de baja en un clic, desde cualquier correo.

Attack Chain

Root causes (what makes the chain work)

  1. Unsanitized SVG upload. The server preserves Content-Type: image/svg+xml
    and serves uploads inline (files.ts).
  2. Top-level blob-URL open. FileAttachment.tsx builds a blob URL from the
    downloaded file and calls window.open(blobUrl). A blob URL loaded as a
    document inherits the creator's origin, so the SVG's <script> runs inside
    NeuroChat's origin.
  3. JWT in localStorage. auth.ts returns the token in the JSON response
    body and the client stores it in localStorage['nc_token'] — reachable from
    any script running in the origin.
  4. Open chat invites. Any user can invite anyone (including admin@) into
    any chat they own.
  5. Eager admin helper. A headless Chromium bot loads the chat and clicks the
    "Open in new tab" button on each attachment, firing the payload.

How to solve

1) Exploration

  • Sign in as attacker, upload an SVG that visibly renders (e.g. a simple shape)
  • Click Open in new tab — observe it opens on a blob: URL
  • Inspect Network tab: /api/files/:id returns Content-Type: image/svg+xml

2) Proof of script exec

Upload an SVG such as:

<svg xmlns="http://www.w3.org/2000/svg" width="120" height="40">
  <text y="25">hi</text>
  <script>alert(document.domain)</script>
</svg>

Click Open in new tab → alert pops on localhost:1338 → Self-XSS confirmed.

3) Weaponize

Your user id is visible in any decoded JWT (or in /admin if seen, but you are
not admin yet — use atob(token.split('.')[1])). Build an SVG that POSTs your
localStorage to /api/exfil/<id> (see exploit.py).

4) Deliver

Upload the weaponized SVG to a chat. Invite admin@neurochat.ai. The bot polls
every ~15s; it will accept, visit the chat, and click the attachment.

5) Harvest

Open /stolen in the UI (or poll /api/exfil). A capture with
email = admin@neurochat.ai will appear.

6) Takeover

Click Hijack session on that capture (or copy the token into
localStorage['nc_token']). Browse to /admin → flag.

Or: just run the exploit

python3 exploit.py

Proof of Concept (automated)

exploit.py automates steps 1–6 end-to-end. Typical run:

[1] Login as attacker@neurochat.ai
    ✓ logged in as #1 (Alex Morgan) · role=user
[2] Create attacker-owned chat
    ✓ chat id = 5
[3] Craft SVG payload (exfil → /api/exfil/1)
    ✓ 1.4 KB
[4] Upload dashboard-mockup.svg
    ✓ mime preserved as image/svg+xml
[5] Post message referencing file
[6] Invite admin@neurochat.ai
[7] Poll /api/exfil for captured admin token
    ✓ captured admin JWT
[8] Hit /api/admin with stolen JWT
      FLAG{e7a15c…}

La comunidad

Esto no es una plataforma con usuarios.Es gente rompiendo lo mismo que tú.

Dentro se pregunta, se enseña lo que se ha encontrado y se resuelve en grupo lo que atascaría a cualquiera solo. Se entra gratis: sin cuenta, sin plan y sin dejar el correo.

Entrar a la comunidad de BBLABS en Discord
Entrar al Discord

Es gratis y abierto. No hace falta tener cuenta en BBLABS para entrar.

BBLABS LogoBBLABS

Laboratorios de hacking basados en hackeos reales. Aprende practicando sobre entornos vulnerables, con la resolución explicada paso a paso.

Producto

  • Funcionalidades
  • Precios
  • Labs
  • Aprender desde 0
  • Blog
  • Detrás de BBLABS

Legal

  • Términos
  • Privacidad
  • Cookies
  • Entrar
  • Crear cuenta

Para cualquier duda, bug, soporte o sugerencia puedes escribir a team@bblabs.es

© 2026 BBLABS. Todos los derechos reservados.