Authorized bug-bounty reproduction

Session Replay zero-click PoC

Enter a client-side ID from a disposable LaunchDarkly environment. This page uses the current official SDK, creates one fresh replay session, and inserts only a harmless console message plus an invalid-path POST canary.

Create the test recording

Use a client-side ID, never a server-side SDK key. The value remains in this browser.

Waiting for a client-side ID.

Recording created

The official ingestion endpoint accepted the finalized payload. LaunchDarkly may still need a short processing delay before the session appears.

Session ID —
Recorded page —
Open session in LaunchDarkly

Open the vulnerable legacy player

  1. Wait until the session shows as processed, then open the session link above.
  2. Open the session’s Tools menu and choose Create heatmap. This produces the correctly locked timestamp automatically.
  3. Simply allow the heatmap page to load. Do not click inside the replay. The console message and invalid-path POST occur automatically.
  4. The click table may temporarily say No clicked elements found; that aggregation is independent of the locked replay loading and does not prevent the canary.
Exact harmless canary