Target:vibe.monday.com (Monday.com Vibe design-system Storybook) Main app:monday.com (HackerOne) XSS type: DOM XSS via postMessage → updateStoryArgs → Link href = javascript: Interaction: 1 click — victim clicks the fullscreen overlay link Impact: Steals logged-in user's email, user ID, account ID, team slug,
and tracking identifiers from non-HttpOnly cookies on .monday.com