Bugpoint
969 subscribers
3.92K photos
3.92K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
IDOR in Stats API Endpoint Allows Viewing Equity or Net Profit of Any MT Account

πŸ‘‰ https://hackerone.com/reports/1644436

πŸ”Ή Severity: No Rating | πŸ’° 1,000 USD
πŸ”Ή Reported To: EXNESS
πŸ”Ή Reported By: #ashwarya
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 5, 2022, 3:50pm (UTC)
πŸ‘9❀2
[Splatoon 3] Kick other players with NplnLogin message

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: Nintendo
πŸ”Ή Reported By: alzxk11
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 2, 2026, 1:25am (UTC)

A vulnerability was discovered that allowed players to kick other players from a Splatoon 3 game using an NplnLogin message.

πŸ‘‰ Read full report
❀1
admin.shopify.com: Shopify Flow continues sending internal emails to a configured recipient after the staff author is removed

πŸ”Ή Severity: None
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: abahack
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: July 3, 2026, 6:50pm (UTC)

πŸ‘‰ Read full report
Any installed app can force immediate logout and persistent DOS of authenticated Basecamp sessions via unprotected exported StartActivity

πŸ”Ή Severity: Medium | πŸ’° 287 USD
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: Basecamp
πŸ”Ή Reported By: zerodaysec_xyz
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 4, 2026, 11:05am (UTC)

A vulnerability was discovered in the Basecamp Android app that allowed any installed app to force immediate logout and persistent denial-of-service of authenticated Basecamp sessions. The vulnerability was due to the `com.basecamp.bc4.app.main.start.StartActivity` being declared as exported without any permission guard. This allowed any app to launch it with an explicit intent, terminating the current session and…

πŸ‘‰ Read full report
OS Command Injection in `aws-cdk-lib` NodejsFunction via Unsanitized `OsCommand` Helper (Supply Chain RCE)

πŸ”Ή Severity: High
πŸ”Ή Weakness: OS Command Injection
πŸ”Ή Reported To: AWS VDP
πŸ”Ή Reported By: kaporia
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 6, 2026, 5:48pm (UTC)

A vulnerability was discovered in the "aws-cdk-lib" NodejsFunction that allowed for OS command injection through the unsanitized "OsCommand" helper. The vulnerability was caused by the lack of proper escaping of user-controlled data when constructing shell commands during Docker-based bundling. This could have potentially led to arbitrary code execution within the Docker container, which had access to the host…

πŸ‘‰ Read full report
Kiro IDE Stores Auth Tokens with World-Readable Permissions (0644)

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Incorrect Default Permissions
πŸ”Ή Reported To: AWS VDP
πŸ”Ή Reported By: mistercloudsec
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 9, 2026, 3:31pm (UTC)

The Kiro IDE (version 0.11.107) wrote authentication tokens (access token and refresh token) to a file with world-readable permissions (0644). The file contained sensitive information, including the access token, refresh token, and profile ARN. This exposed the credentials to potential unauthorized access by local processes or users.

πŸ‘‰ Read full report
πŸ‘1
Unauthenticated Access to MMGIS Webhooks

πŸ”Ή Severity: High
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: oversudo
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 7, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Unauthenticated Disclosure of NASA Organizer Email Addresses via The Events Calendar REST API (CVE-2025-9808)

πŸ”Ή Severity: Informational
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: ARTanvir76
πŸ”Ή State: βšͺ️ Informational
πŸ”Ή Disclosed: July 9, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
[Atlas Browser] Fullscreen Toast Can Be Hidden by Repeated Constraint Validation Popups

πŸ”Ή Severity: Low
πŸ”Ή Reported To: OpenAI
πŸ”Ή Reported By: jodyritonga
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 9, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
πŸ‘‹ Hey hunters!

The channel just leveled up β€” disclosed reports now pull from two sources: HackerOne & Bugcrowd 🐞πŸ”₯

More features are on the way πŸš€ And you get a say β€” which platform should we plug in next? React to vote πŸ‘‡

πŸ”₯ β€” Immunefi (web3)
πŸ‘ β€” huntr (open source)
πŸ€” β€” something else (tell us in comments)
❀5πŸ”₯3πŸ‘2πŸ€”2
Unauthenticated Error-Based SQL Injection in HEASARC W3Browse w3hdprods.pl

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: Anon0x0
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 13, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
SELECT ... INTO OUTFILE does not enforce the FILE WRITE privilege unprivileged arbitrary file write on the server

πŸ”Ή Severity: High
πŸ”Ή Weakness: Missing Authorization
πŸ”Ή Reported To: SingleStore
πŸ”Ή Reported By: bisht-ji
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 13, 2026, 7:35pm (UTC)
🐞 Source: HackerOne

A security vulnerability was reported in SingleStore's self-managed database server where the SELECT...INTO OUTFILE command did not properly enforce the FILE WRITE privilege. This allowed any authenticated user, including those with only USAGE privileges, to write arbitrary files to the aggregator host at any path, written as the engine OS user. The vulnerability affected default-configuration self-managed…

πŸ‘‰ Read full report
πŸ‘1
One-Click Data Exfiltration via rovoChatPrompt URL Parameter (Confluence / Rovo)

πŸ”Ή Severity: High
πŸ”Ή Reported To: Atlassian
πŸ”Ή Reported By: loacker
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 14, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Clickjacking Vulnerability – cdn.sit.earthdata.nasa.gov

πŸ”Ή Severity: Informational
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: SAIJAYANTH
πŸ”Ή State: βšͺ️ Informational
πŸ”Ή Disclosed: July 14, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
bedrock-mantle.api.aws accepts Bedrock API keys outside the IAM Deny, CloudTrail signal, and invocation logging AWS publishes for Bedrock keys

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Insecure Default Initialization of Resource
πŸ”Ή Reported To: AWS VDP
πŸ”Ή Reported By: mistercloudsec
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 14, 2026, 6:52pm (UTC)
🐞 Source: HackerOne

A second Bedrock API key-accepting service plane called "bedrock-mantle" was discovered. This plane was not described in AWS's customer-facing Bedrock documentation. As a result, the AWS-published security controls to detect and prevent Bedrock API key abuse failed to apply to the bedrock-mantle plane. Specifically, the IAM deny policy, CloudTrail detection signal, and model invocation logging configuration were…

πŸ‘‰ Read full report
Stored XSS on Trix Editor version latest (2.1.16) - Sanitizer Bypass

πŸ”Ή Severity: Low | πŸ’° 337 USD
πŸ”Ή Weakness: Cross-site Scripting (XSS) - Stored
πŸ”Ή Reported To: Basecamp
πŸ”Ή Reported By: newbiefromcoma
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 14, 2026, 7:26pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in Trix Editor version 2.1.16 that allowed for a Stored Cross-Site Scripting (XSS) attack. The vulnerability arose from an unsafe interaction between Trix's custom DOMPurify configuration and its document serialization logic. The issue was caused by Trix's use of the "data-trix-serialized-attributes" attribute, which was not properly sanitized during the serialization process…

πŸ‘‰ Read full report
Bedrock AgentCore Starter Toolkit Creates Gateway IAM Roles Without Confused Deputy Protections

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Incorrect Permission Assignment for Critical Resource
πŸ”Ή Reported To: AWS VDP
πŸ”Ή Reported By: mistercloudsec
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 15, 2026, 3:12pm (UTC)
🐞 Source: HackerOne

The Bedrock AgentCore Starter Toolkit was found to create IAM roles for the AgentCore Gateway with trust policies that lacked certain condition keys. This enabled a cross-account confused deputy attack where any AgentCore workload in any AWS account could assume the victim's Gateway role. The role granted access to sensitive resources in the account, including secrets, KMS, Lambda, DynamoDB, and S3.

πŸ‘‰ Read full report
Able to bypass authorization logic and gain more access then intended

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: GitHub
πŸ”Ή Reported By: vaib25vicky
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 15, 2026, 4:35pm (UTC)
🐞 Source: HackerOne

A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. The vulnerability was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, and 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.

πŸ‘‰ Read full report
Stored XSS in Rocket.Chat HTML File Export β€” Unauthenticated Entry via LiveChat

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Cross-site Scripting (XSS) - Stored
πŸ”Ή Reported To: Rocket.Chat
πŸ”Ή Reported By: olidayw
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 16, 2026, 5:02am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the HTML file export feature of Rocket.Chat. The vulnerability allowed an attacker to inject arbitrary JavaScript code that would execute when the exported HTML file was opened. The root cause was that the application did not properly sanitize or escape user-supplied data before including it in the exported HTML. As a result, an unauthenticated attacker could leverage the…

πŸ‘‰ Read full report
πŸ”₯1
πŸ’Έ Top 10 biggest bounties ever paid on HackerOne

Publicly disclosed. Real payouts. One bug each πŸ‘‡

πŸ₯‡ $50,000 β€” Shopify
GitHub access token exposure Β· augustozanellato

πŸ₯ˆ $39,999 β€” Uber
API access Β· tomnomnom

πŸ₯‰ $35,000 β€” GitLab
Account takeover via password reset Β· asterion04

4️⃣ $33,510 β€” GitLab
RCE via GitHub import Β· vakzz

5️⃣ $30,000 β€” PayPal
Dependency confusion RCE Β· alexbirsan

6️⃣ $29,000 β€” GitLab
Arbitrary file read Β· vakzz

7️⃣ $25,000 β€” Valve
SQL injection in report_xml.php Β· moskowsky

8️⃣ $25,000 β€” Snapchat
Exposed Kubernetes API β†’ RCE Β· txt3rob

9️⃣ $25,000 β€” HackerOne
Disclosing a private program Β· haxta4ok00

πŸ”Ÿ $20,160 β€” X / xAI
Pre-auth RCE Β· orange

πŸ’‘ And these are just the public ones β€” the biggest private bounties go way higher.

Which one surprises you most? 🀯
πŸ”₯1
Bugpoint pinned Β«πŸ’Έ Top 10 biggest bounties ever paid on HackerOne Publicly disclosed. Real payouts. One bug each πŸ‘‡ πŸ₯‡ $50,000 β€” Shopify GitHub access token exposure Β· augustozanellato πŸ₯ˆ $39,999 β€” Uber API access Β· tomnomnom πŸ₯‰ $35,000 β€” GitLab Account takeover via password…»