Monday.com — Storybook XSS → PII Theft

Target: vibe.monday.com (Monday.com Vibe design-system Storybook)
Main app: monday.com (HackerOne)
XSS type: DOM XSS via postMessageupdateStoryArgs → Link href = javascript:
Interaction: 1 click — victim clicks the fullscreen overlay link
Impact: Steals logged-in user's email, user ID, account ID, team slug, and tracking identifiers from non-HttpOnly cookies on .monday.com

PII Captured from Logged-In Monday User