franceconnect-proconnect-public

YesWeHackView on YesWeHack
RawAI Enhanced
5
In Scope
4
Out of Scope
In-Scope Assets (5)
Out-of-Scope Assets (4)
AssetCategoryBounty
All partners and all mocks are out of scope (but you can use the deployed mocks at your discretion to attack the scope).OTHERYes
The production environment (*.gouv.fr) is out of scope.OTHERYes
The local stack (*.docker.dev-franceconnect) is a powerful tool for you to understand the internals processes but is out of scope (the exploit should as well work in the scope to qualify).OTHERYes
https://fcp.integ01.dev-franceconnect.frOTHERYes
Scope Changes (31)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedfranceconnect (see program description for github link)OTHERIn Scope19:08
Addedall partners and all mocks are out of scope (but you can use the deployed mocks at your discretion to attack the scope)OTHEROut of Scope19:08
Addedthe local stack (*.docker.dev-franceconnect) is a powerful tool for you to understand the internals processes but is out of scope (the exploit should as well work in the scope to qualify)WILDCARDOut of Scope19:08
Addedthe production environment (*.gouv.fr) is out of scopeWILDCARDOut of Scope19:08
Addedfranceconnect+ (see program description for github link)OTHERIn Scope19:08
Addedeidas bridge (see program description for github link)OTHERIn Scope19:08
Addeduser dashboard (see program description for github link)OTHERIn Scope19:08
Addedhttps://fcp.integ01.dev-franceconnect.frURLOut of Scope19:08
Addedspecific scenarios (see program description)OTHERIn Scope19:08
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedthe production environment (*.gouv.fr) is out of scopeWILDCARDOut of Scope00:51
Addedhttps://fcp.integ01.dev-franceconnect.frURLOut of Scope00:51
Addedfranceconnect+ (see program description for github link)URLIn Scope00:51
Addedfranceconnect (see program description for github link)URLIn Scope00:51
Addedall partners and all mocks are out of scope (but you can use the deployed mocks at your discretion to attack the scope)OTHEROut of Scope00:51
Addedspecific scenarios (see program description)OTHERIn Scope00:51
Addedeidas bridge (see program description for github link)URLIn Scope00:51
Addeduser dashboard (see program description for github link)URLIn Scope00:51
Addedthe local stack (*.docker.dev-franceconnect) is a powerful tool for you to understand the internals processes but is out of scope (the exploit should as well work in the scope to qualify)WILDCARDOut of Scope00:51
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removedspecific scenarios (see program description)OTHERIn Scope21:40
Removedfranceconnect+ (see program description for github link)URLIn Scope21:40
Removedfranceconnect (see program description for github link)URLIn Scope21:40
Removedeidas bridge (see program description for github link)URLIn Scope21:40
Removeduser dashboard (see program description for github link)URLIn Scope21:40
Removedall partners and all mocks are out of scope (but you can use the deployed mocks at your discretion to attack the scope)OTHEROut of Scope21:40
Removedthe local stack (*.docker.dev-franceconnect) is a powerful tool for you to understand the internals processes but is out of scope (the exploit should as well work in the scope to qualify)OTHEROut of Scope21:40
Removedthe production environment (*.gouv.fr) is out of scopeOTHEROut of Scope21:40
Removedhttps://fcp.integ01.dev-franceconnect.frOTHEROut of Scope21:40
Addedthe local stack (*.docker.dev-franceconnect) is a powerful tool for you to understand the internals processes but is out of scope (the exploit should as well work in the scope to qualify)OTHEROut of Scope00:33
Addedthe production environment (*.gouv.fr) is out of scopeOTHEROut of Scope00:33
Addedhttps://fcp.integ01.dev-franceconnect.frOTHEROut of Scope00:33
Addedall partners and all mocks are out of scope (but you can use the deployed mocks at your discretion to attack the scope)OTHEROut of Scope00:33