Program Removed

This program is no longer available on YesWeHack. The scope data shown below is historical and may not reflect the final state of the program.

franceconnect-proconnect-public

YesWeHackView on YesWeHack
RawAI Enhanced
9
In Scope
7
Out of Scope
In-Scope Assets (9)
AssetCategoryBountyQuick Links
eidas bridgeOTHERYes-
eidas bridgeURLYes-
franceconnectOTHERYes-
franceconnectURLYes-
franceconnect+OTHERYes-
franceconnect+URLYes-
specific scenarios (see program description)OTHERYes-
user dashboardURLYes-
user dashboardOTHERYes-
Out-of-Scope Assets (7)
AssetCategoryBounty
all partners and all mocks are out of scope (but you can use the deployed mocks at your discretion to attack the scope)OTHERYes
docker.dev-franceconnectWILDCARDYes
gouv.frWILDCARDYes
https://fcp.integ01.dev-franceconnect.frURLYes
https://fcp.integ01.dev-franceconnect.frOTHERNo
the production environment (*.gouv.fr) is out of scopeOTHERNo
the local stack (*.docker.dev-franceconnect) is a powerful tool for you to understand the internals processes but is out of scope (the exploit should as well work in the scope to qualify)OTHERNo
Scope Changes (32)
Mar 30, 2026
ChangeAssetCategoryScopeTime
Program Removed09:21
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedfranceconnect (see program description for github link)OTHERIn Scope19:08
Addedall partners and all mocks are out of scope (but you can use the deployed mocks at your discretion to attack the scope)OTHEROut of Scope19:08
Addedthe local stack (*.docker.dev-franceconnect) is a powerful tool for you to understand the internals processes but is out of scope (the exploit should as well work in the scope to qualify)WILDCARDOut of Scope19:08
Addedthe production environment (*.gouv.fr) is out of scopeWILDCARDOut of Scope19:08
Addedfranceconnect+ (see program description for github link)OTHERIn Scope19:08
Addedeidas bridge (see program description for github link)OTHERIn Scope19:08
Addeduser dashboard (see program description for github link)OTHERIn Scope19:08
Addedhttps://fcp.integ01.dev-franceconnect.frURLOut of Scope19:08
Addedspecific scenarios (see program description)OTHERIn Scope19:08
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedthe production environment (*.gouv.fr) is out of scopeWILDCARDOut of Scope00:51
Addedhttps://fcp.integ01.dev-franceconnect.frURLOut of Scope00:51
Addedfranceconnect+ (see program description for github link)URLIn Scope00:51
Addedfranceconnect (see program description for github link)URLIn Scope00:51
Addedall partners and all mocks are out of scope (but you can use the deployed mocks at your discretion to attack the scope)OTHEROut of Scope00:51
Addedspecific scenarios (see program description)OTHERIn Scope00:51
Addedeidas bridge (see program description for github link)URLIn Scope00:51
Addeduser dashboard (see program description for github link)URLIn Scope00:51
Addedthe local stack (*.docker.dev-franceconnect) is a powerful tool for you to understand the internals processes but is out of scope (the exploit should as well work in the scope to qualify)WILDCARDOut of Scope00:51
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removedspecific scenarios (see program description)OTHERIn Scope21:40
Removedfranceconnect+ (see program description for github link)URLIn Scope21:40
Removedfranceconnect (see program description for github link)URLIn Scope21:40
Removedeidas bridge (see program description for github link)URLIn Scope21:40
Removeduser dashboard (see program description for github link)URLIn Scope21:40
Removedall partners and all mocks are out of scope (but you can use the deployed mocks at your discretion to attack the scope)OTHEROut of Scope21:40
Removedthe local stack (*.docker.dev-franceconnect) is a powerful tool for you to understand the internals processes but is out of scope (the exploit should as well work in the scope to qualify)OTHEROut of Scope21:40
Removedthe production environment (*.gouv.fr) is out of scopeOTHEROut of Scope21:40
Removedhttps://fcp.integ01.dev-franceconnect.frOTHEROut of Scope21:40
Addedthe local stack (*.docker.dev-franceconnect) is a powerful tool for you to understand the internals processes but is out of scope (the exploit should as well work in the scope to qualify)OTHEROut of Scope00:33
Addedthe production environment (*.gouv.fr) is out of scopeOTHEROut of Scope00:33
Addedhttps://fcp.integ01.dev-franceconnect.frOTHEROut of Scope00:33
Addedall partners and all mocks are out of scope (but you can use the deployed mocks at your discretion to attack the scope)OTHEROut of Scope00:33