bug-bounty-program-blablacar

YesWeHackView on YesWeHack
RawAI Enhanced
11
In Scope
4
Out of Scope
In-Scope Assets (11)
Out-of-Scope Assets (4)
AssetCategoryBounty
Any website that is not listed explicitly in the scope.OTHERYes
Finally, fraud related reports are out-of-scope if they do not exploit a security vulnerability. Therefore, fraud activity enabled by bug or incomplete business rules enforcement are out-of-scope. However, a fraud activity enabled by a CSRF exploit for example is valid.OTHERYes
However, though listed in the out-of-scope list, if you really feel that a bug will leave an impact on our platform, please come up with a convincing and working POC. If that convinces us to change our code, we will reward you with a bounty.OTHERYes
Please note that https://dev.blablacar.com is hosted by a third party and thus is out of scope.OTHERYes
Scope Changes (15)
Apr 16, 2026
ChangeAssetCategoryScopeTime
Addedhttps://edge.blablacar.(fr|de|co.uk|in|es|mx|be|hr|hu|it|nl|pl|com.br|pt|ro|ru|com|tr|com.ua))URLIn Scope18:33
Addedhttps://auth.blablacar.(fr|de|co.uk|in|es|mx|be|hr|hu|it|nl|pl|com.br|pt|ro|ru|com|tr|com.ua)URLIn Scope18:33
Addedhttps://www.blablacar.(fr|de|co.uk|in|es|mx|be|hr|hu|it|nl|pl|com.br|pt|ro|ru|com|tr|com.ua)URLIn Scope18:33
Addedhttps://m.blablacar.(fr|de|co.uk|in|es|mx|be|hr|hu|it|nl|pl|com.br|pt|ro|ru|com|tr|com.ua)URLIn Scope18:33
Addedhttps://play.google.com/store/apps/details?id=com.comuto&hl=enANDROIDIn Scope18:33
Addedhttps://itunes.apple.com/fr/app/blablacar-trusted-carpooling/id341329033?l=en&mt=8IOSIn Scope18:33
Addedhttps://api.blablalines.comURLIn Scope18:33
Addedhttps://daily.blablacar.frURLIn Scope18:33
Addedhttps://blablacardaily.comURLIn Scope18:33
Addedhttps://play.google.com/store/apps/details?id=com.blablalinesANDROIDIn Scope18:33
Addedhttps://apps.apple.com/fr/app/blablalines-covoiturage/id1225543288IOSIn Scope18:33
Addedplease note that https://dev.blablacar.com is hosted by a third party and thus is out of scopeOTHEROut of Scope18:33
Addedany website that is not listed explicitly in the scopeOTHEROut of Scope18:33
Addedhowever, though listed in the out-of-scope list, if you really feel that a bug will leave an impact on our platform, please come up with a convincing and working poc. if that convinces us to change our code, we will reward you with a bountyOTHEROut of Scope18:33
Addedfinally, fraud related reports are out-of-scope if they do not exploit a security vulnerability. therefore, fraud activity enabled by bug or incomplete business rules enforcement are out-of-scope. however, a fraud activity enabled by a csrf exploit for example is validOTHEROut of Scope18:33