# Episode 168: XSSDoctor - Client-side Path Traversal Research Page: https://stenobird.com/podcast/critical-thinking-bug-bounty-podcast-5951018/episode-168-xssdoctor-client-side-path-traversal-research Text version: https://stenobird.com/podcast/critical-thinking-bug-bounty-podcast-5951018/episode-168-xssdoctor-client-side-path-traversal-research.md Podcast: [Critical Thinking - Bug Bounty Podcast](https://stenobird.com/podcast/critical-thinking-bug-bounty-podcast-5951018) Published: 2026-04-02T09:00:00+00:00 Episode link: https://criticalthinkingpodcast.io Audio file: https://audio-delivery.cohostpodcasting.com/audio/8d5e4388-13f4-45c8-b82f-aff313a5ac76/episodes/130ca433-aeed-4bbb-a828-0d1a024882ea/episode.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/critical-thinking-bug-bounty-podcast-5951018/episodes/episode-168-xssdoctor-client-side-path-traversal-research Duration seconds: 5755 ## Resource Episode 168: In this episode of Critical Thinking - Bug Bounty Podcast we’re getting a visit from the XSS Doctor. Jonathan joins us to go through his Client-side workflow, run labs, and diagnose some bugs live. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/   ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Today’s Guest: https://x.com/xssdoctor ====== Resources ====== The Dot-Dot-Slash That Frameworks Hand You: CSPT Across Every Major Frontend Framework https://lab.ctbb.show/research/the-dot-dot-slash-that-frameworks-hand-you URL validation bypass cheat sheet https://portswigger.net/web-security/ssrf/url-validation-bypass-cheat-sheet ====== Timestamps ====== (00:00:00) Introduction (00:01:37) Home Automation AI Hack & E-signature bug stories (00:12:15) E-signature bug (00:17:01) XSS DR Intro and Bug Bounty Journey (00:31:51) CSPT Workflows (01:07:57) Wildcard Path Parameters  (01:30:34) Custom Sinks ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/critical-thinking-bug-bounty-podcast-5951018/episodes/episode-168-xssdoctor-client-side-path-traversal-research/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/critical-thinking-bug-bounty-podcast-5951018/episode-168-xssdoctor-client-side-path-traversal-research.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.