Observed arrival · 2026-09-30
A domain that demonstrates a Booksy origin-check flaw
Credibility concern recorded. The source reference remains available for verification and correction.
This security-research page runs a browser-side probe against Booksy’s dedicated bug-bounty test environment after a visitor signs into Booksy Biz in the same browser.
- For
- Booksy security staff and browser-security researchers
- Worth noticing
- It contrasts `booksy.com`, `notreallybooksy.com`, and `booksy.com.evil.net`, then suggests an anchored regex or exact-origin allowlist.
Field notes
The page's sequence is explicit: sign into Booksy Biz in the same browser, return, then run again; it says a session-free run finds nothing and does not demonstrate impact. In the extracted view, the result area was still waiting and no raw messages were shown. The researcher says the code runs in the browser without storage or transmission and uses a dedicated test account.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue