bubblescan
Offensive security toolkit for Bubble.io applications — 12 modules covering reconnaissance, configuration audit, and data extraction, driven from a single interactive CLI. Includes a working implementation of the Elasticsearch crypto bypass publicly disclosed in April 2025.
Author: @Siin0pe · License: MIT
Features
Reconnaissance (read-only, passive)
fingerprint— detect Bubble.io, extractappname, session tokens, API keys, CDN/infraplugins— enumerate Bubble plugins (first-party + marketplace), optionally enrich from the Bubble plugin storedatatypes— list every custom data type and its fields fromstatic.js+/init/datapages— enumerate Bubble pages via wordlist (live +/version-test/)elements— rebuild the UI element tree fromdynamic.jssecrets— scan HTML + bundles for tokens, API keys, URL secrets; verify exposed Google keys
Audit (active, read-only probing)
config-audit— security headers, public-editor check, live vs/version-test/diffplugin-audit— flag deprecated / leak-prone plugins, detect third-party data-leak hostsapi-probe— map the Data API and Workflow API surface (meta, obj, wf, swagger)files— enumerate S3/CDN URLs, test anon access, probe/fileupload, optional type-fuzz
Exploit
es-audit— Elasticsearch crypto bypass: probe, analyze, dump, forge, encrypt/decryptworkflows— audit workflow API, detect anon-reachable and temp-password-leaking workflows
Reporting
- One
Contextcollects findings across every module - Export as Markdown, HTML, or JSON from a single
reportcommand - Optional
--checkpointsnapshots after each step
Install
Requires Python 3.11+.
pipx install bubblescan
Verify:
bubblescan --version
bubblescan modules
Reports and dumps land under ./out/ by default, so run bubblescan from the
directory you want the artefacts written to.
Usage
Three paths, from simplest to most complete.
1. Quick fingerprint
Single module, one-shot, no state to manage. Good for confirming a target is a
Bubble.io app and grabbing the appname, session tokens, keys, and infra:
bubblescan run fingerprint https://app.example.com
2. Full audit + report
Run every module (recon → audit → exploit) in the right order and export a structured report:
bubblescan flow full https://app.example.com --export out/report.html
.md, .html, and .json are all supported — the extension picks the format.
Add --open to pop the report in your browser when the flow finishes.
Shorter variants:
bubblescan flow recon https://app.example.com # passive only
bubblescan flow audit https://app.example.com # + active probing
bubblescan flow crypto https://app.example.com # ES bypass end-to-end
bubblescan report https://app.example.com out/report.html # alias for `flow full --export`
3. Interactive shell
For iterative work — pick modules, inspect findings, export at the end:
bubblescan # launches the REPL
bubblescan ❯ target https://app.example.com
bubblescan ❯ session load session.json # optional, authenticated session
bubblescan ❯ modules # list modules by phase
bubblescan ❯ help es-audit # module-specific help
bubblescan ❯ flow recon # chain modules
bubblescan ❯ run es-audit analyze --field-leak # single module with flags
bubblescan ❯ findings # review what was captured
bubblescan ❯ report out/session.html
Tab-completion works on commands, modules, and targets. History persists to
~/.bubblescan_history.
Flow presets
| Preset | Chain |
|---|---|
recon |
fingerprint → plugins → pages → datatypes → elements → secrets |
audit |
fingerprint → plugins → config-audit → plugin-audit → api-probe → files (enumerate / test-public / upload-probe) |
crypto |
fingerprint → datatypes → es-audit probe → es-audit analyze --field-leak |
exploit |
fingerprint → datatypes → es-audit analyze → workflows analyze |
full |
recon + audit + exploit (deduplicated) |
Every preset accepts --export <path>, --open, and --checkpoint.
Environment
| Variable | Effect |
|---|---|
BUBBLESCAN_LOCAL_DUMP=<dir> |
Offline mode. HTTP fetches fall back to files in that directory when a matching path exists. Useful for regression tests against a cached mirror. |
BUBBLESCAN_CACHE_DIR=<dir> |
Override the default bundle cache location (~/.cache/bubblescan/bundles). |
BUBBLESCAN_NO_UPDATE_CHECK=1 |
Disable the passive PyPI update check at startup (also auto-skipped when stdout is not a TTY). |
Documentation
docs/cli.md— shell command referencedocs/modules.md— module-by-module referencedocs/workflows.md— recipes and end-to-end sessionsdocs/architecture.md— code map for contributorsdocs/crypto.md— Elasticsearch crypto protocol
Elasticsearch crypto bypass
Short version: every Bubble SPA encrypts its Elasticsearch requests into a
three-part envelope {x, y, z} before sending them, but the entire derivation
hinges on a value every client receives in plaintext — the appname slug. The
scheme was reverse-engineered and published in April 2025 by Lucca & Pedro
(demon-i386/pop_n_bubble,
GBHackers coverage).
- Cipher: AES-256-CBC + PKCS7
- KDF: PBKDF2-HMAC-MD5 with 7 iterations,
appnameas salt - Constant IV seeds
po9/fl1, identical across every Bubble app - No authentication on the endpoint itself — Bubble has not issued a patch
bubblescan re-implements the primitives from scratch (no upstream code) and
exposes them through es-audit: probe, analyze, dumpone, dumpall,
query, encrypt, decrypt. See docs/crypto.md for the
full protocol spec and docs/modules.md#es-audit for the
subcommand reference.
Contributing
Ideas, bug reports, and new modules are very welcome.
- Bug reports / feature requests: open an issue with the (anonymised) target context, the command you ran, and the output.
- New modules: follow the short guide in
docs/architecture.md. Anything dropped intobubblescan/modules/is auto-discovered. - Pull requests: keep them focused, match existing patterns, and add a
one-line entry to the relevant
docs/*.mdwhen user-visible.
The project is intentionally small — reading three or four modules is enough to get the conventions.
Disclaimer & authorized use
bubblescan is an offensive security research tool. Running it implies
acceptance of the terms below.
- Authorized testing only. Use
bubblescanonly against systems you own or that you have prior written authorization to test (formal engagement, bug-bounty scope, CTF, training lab). - Unauthorized use is prohibited and is the sole responsibility of the end user. The author accepts no liability for it.
- Public disclosure. The Elasticsearch bypass targets a Bubble.io flaw that was publicly disclosed in April 2025 by Lucca & Pedro; this project re-implements the primitives from the public specification independently.
- No affiliation.
bubblescanis not affiliated with, endorsed by, or sponsored by Bubble Group, Inc. - No warranty. Software provided "as is" per the MIT
LICENSE.
Responsible disclosure
- Vulnerability in a Bubble.io app you discover with this tool: report it privately to the application owner with a reasonable fix window (typically 90 days) before any public disclosure.
Credits
- Tool design and implementation: @Siin0pe.
- Cryptographic scheme research: Pablo and Lucca, published April 2025 via
demon-i386/pop_n_bubblewith coverage from GBHackers, Cyberpress, SecurityOnline, and TechNADU.bubblescanre-implements the primitives independently and wraps them in eleven additional modules covering the rest of the Bubble.io attack surface.
Release files for bubblescan 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| bubblescan-0.2.0.tar.gz | 139.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| bubblescan-0.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 288.2 kB
Release files / bubblescan-0.2.0.tar.gz
| Download URL | bubblescan-0.2.0.tar.gz |
|---|---|
| Size | 139.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f4ff2cb6e9c3ec5b67a0b2be503882417902d0af749c977b920e8da743afd734
|
|
BLAKE2b-256 checksum How to use checksums |
755fecfd4d9790c4d57aed4fae9402afa91a36c7df1b4bbea5ec3d7a08903e72
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 13, 2026.
Transparency logRelease files / bubblescan-0.2.0-py3-none-any.whl
| Download URL | bubblescan-0.2.0-py3-none-any.whl |
|---|---|
| Size | 148.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
34a5e85bec295a9b9921d5e6b2862876ace5d175ff10a332cffc73797d30fa72
|
|
BLAKE2b-256 checksum How to use checksums |
fab3e55d53cfed2eaa33c4673fc09f4284df344ead19921138349c934b8bb30b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 13, 2026.
Transparency log