Public Storybook · Tenant invitation chain

Cross-origin message.
Authenticated tenant access.

A hosted two-account reproduction: arbitrary-origin postMessage reaches a javascript: sink, then the resulting Storybook XSS frames an authenticated team-management action.

01Primitive

Confirm document.domain execution

Open the public preview, inject a javascript: destination through updateStoryArgs, and click the full-page Storybook link once.

Ready. Allow pop-ups for this origin.

02E2E impact

Invite a controlled account into the tenant

Use only two accounts you control. The injected page opens in functional mode, leaving the real framed Metronome controls visible and interactive. An optional redress view demonstrates the click-through overlay.

Ready. Sign in to the researcher-owned Account A before starting. Recipient: poch1@noexist.com.

  1. Sign in to Metronome team settings as Account A.
  2. Run the chain and click the full-page Storybook link once.
  3. In the popup, use the real Metronome Add button and modal. Copy or type PoC Account and poch1@noexist.com, then use the real Add user button.
  4. Optionally select Show redress view to demonstrate that its outlined targets still click through to the framed controls.
  5. Open Account B’s inbox, set its password from the welcome email, and sign in to confirm tenant access.

No collection endpoint · no cookies or bearer tokens read · fixed recipient disclosed before execution

Targetstorybook.metronome.com
Framed actionapp.metronome.com/account/team
Required interactionOne Storybook click + real framed form
PersistenceControlled tenant invitation