Bugpoint
969 subscribers
3.92K photos
3.92K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
bedrock-mantle.api.aws accepts Bedrock API keys outside the IAM Deny, CloudTrail signal, and invocation logging AWS publishes for Bedrock keys

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Insecure Default Initialization of Resource
πŸ”Ή Reported To: AWS VDP
πŸ”Ή Reported By: mistercloudsec
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 14, 2026, 6:52pm (UTC)
🐞 Source: HackerOne

A second Bedrock API key-accepting service plane called "bedrock-mantle" was discovered. This plane was not described in AWS's customer-facing Bedrock documentation. As a result, the AWS-published security controls to detect and prevent Bedrock API key abuse failed to apply to the bedrock-mantle plane. Specifically, the IAM deny policy, CloudTrail detection signal, and model invocation logging configuration were…

πŸ‘‰ Read full report
Stored XSS on Trix Editor version latest (2.1.16) - Sanitizer Bypass

πŸ”Ή Severity: Low | πŸ’° 337 USD
πŸ”Ή Weakness: Cross-site Scripting (XSS) - Stored
πŸ”Ή Reported To: Basecamp
πŸ”Ή Reported By: newbiefromcoma
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 14, 2026, 7:26pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in Trix Editor version 2.1.16 that allowed for a Stored Cross-Site Scripting (XSS) attack. The vulnerability arose from an unsafe interaction between Trix's custom DOMPurify configuration and its document serialization logic. The issue was caused by Trix's use of the "data-trix-serialized-attributes" attribute, which was not properly sanitized during the serialization process…

πŸ‘‰ Read full report
Bedrock AgentCore Starter Toolkit Creates Gateway IAM Roles Without Confused Deputy Protections

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Incorrect Permission Assignment for Critical Resource
πŸ”Ή Reported To: AWS VDP
πŸ”Ή Reported By: mistercloudsec
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 15, 2026, 3:12pm (UTC)
🐞 Source: HackerOne

The Bedrock AgentCore Starter Toolkit was found to create IAM roles for the AgentCore Gateway with trust policies that lacked certain condition keys. This enabled a cross-account confused deputy attack where any AgentCore workload in any AWS account could assume the victim's Gateway role. The role granted access to sensitive resources in the account, including secrets, KMS, Lambda, DynamoDB, and S3.

πŸ‘‰ Read full report
Able to bypass authorization logic and gain more access then intended

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: GitHub
πŸ”Ή Reported By: vaib25vicky
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 15, 2026, 4:35pm (UTC)
🐞 Source: HackerOne

A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. The vulnerability was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, and 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.

πŸ‘‰ Read full report
Stored XSS in Rocket.Chat HTML File Export β€” Unauthenticated Entry via LiveChat

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Cross-site Scripting (XSS) - Stored
πŸ”Ή Reported To: Rocket.Chat
πŸ”Ή Reported By: olidayw
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 16, 2026, 5:02am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the HTML file export feature of Rocket.Chat. The vulnerability allowed an attacker to inject arbitrary JavaScript code that would execute when the exported HTML file was opened. The root cause was that the application did not properly sanitize or escape user-supplied data before including it in the exported HTML. As a result, an unauthenticated attacker could leverage the…

πŸ‘‰ Read full report
πŸ”₯1
πŸ’Έ Top 10 biggest bounties ever paid on HackerOne

Publicly disclosed. Real payouts. One bug each πŸ‘‡

πŸ₯‡ $50,000 β€” Shopify
GitHub access token exposure Β· augustozanellato

πŸ₯ˆ $39,999 β€” Uber
API access Β· tomnomnom

πŸ₯‰ $35,000 β€” GitLab
Account takeover via password reset Β· asterion04

4️⃣ $33,510 β€” GitLab
RCE via GitHub import Β· vakzz

5️⃣ $30,000 β€” PayPal
Dependency confusion RCE Β· alexbirsan

6️⃣ $29,000 β€” GitLab
Arbitrary file read Β· vakzz

7️⃣ $25,000 β€” Valve
SQL injection in report_xml.php Β· moskowsky

8️⃣ $25,000 β€” Snapchat
Exposed Kubernetes API β†’ RCE Β· txt3rob

9️⃣ $25,000 β€” HackerOne
Disclosing a private program Β· haxta4ok00

πŸ”Ÿ $20,160 β€” X / xAI
Pre-auth RCE Β· orange

πŸ’‘ And these are just the public ones β€” the biggest private bounties go way higher.

Which one surprises you most? 🀯
πŸ”₯1
Bugpoint pinned Β«πŸ’Έ Top 10 biggest bounties ever paid on HackerOne Publicly disclosed. Real payouts. One bug each πŸ‘‡ πŸ₯‡ $50,000 β€” Shopify GitHub access token exposure Β· augustozanellato πŸ₯ˆ $39,999 β€” Uber API access Β· tomnomnom πŸ₯‰ $35,000 β€” GitLab Account takeover via password…»
Restricted RPC leaks alternative block hashes via /get_alt_blocks_hashes

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: int0ha_
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 20, 2026, 12:15am (UTC)
🐞 Source: HackerOne

The `/get_alt_blocks_hashes` RPC endpoint was restricted to prevent unintended access to alternative block hashes. The endpoint had previously been unrestricted.

πŸ‘‰ Read full report
❀1
Blind Enumeration of Private Card Names via Sort Oracle and ID Discovery

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Trello
πŸ”Ή Reported By: BobAshEf
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 20, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Public Google Maps API key on www.globe.gov allows Geocoding API calls (billable use)

πŸ”Ή Severity: Informational
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: madhu873
πŸ”Ή State: βšͺ️ Informational
πŸ”Ή Disclosed: July 21, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
OAuth redirect uri validation bypass for :proxima_first_party_sync apps

πŸ”Ή Severity: High
πŸ”Ή Weakness: Open Redirect
πŸ”Ή Reported To: GitHub
πŸ”Ή Reported By: ahacker1
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 21, 2026, 9:43pm (UTC)
🐞 Source: HackerOne

A vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI validation. The vulnerability was fixed in versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, and 3.14.26. The vulnerability was reported through the GitHub Bug Bounty program.

πŸ‘‰ Read full report
connect.8x8.com/api/v1: JWT Algorithm Confusion Vulnerability

πŸ”Ή Severity: High | πŸ’° 1,337 USD
πŸ”Ή Weakness: Improper Verification of Cryptographic Signature
πŸ”Ή Reported To: 8x8
πŸ”Ή Reported By: kyotozzx
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 22, 2026, 4:15am (UTC)
🐞 Source: HackerOne

A JWT algorithm confusion vulnerability was reported in the `v1` API of `connect.8x8.com`. The JWT verifier did not enforce algorithm pinning and would accept HS256 tokens signed with the RSA public key used as an HMAC secret. The issue was remediated by enforcing RS256 algorithm pinning in the `v1` API verifier.

πŸ‘‰ Read full report
GitHub user to server tokens can create issues in any public repository

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: GitHub
πŸ”Ή Reported By: ahacker1
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 22, 2026, 7:39pm (UTC)
🐞 Source: HackerOne

A vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope. The authorization check only verified that the installation had read permissions on the target repository rather than verifying that the token's installation was explicitly granted access to…

πŸ‘‰ Read full report
AWS *.a2z.com | Unauthenticated Clickhouse UI : Database access + SSRF

πŸ”Ή Severity: High
πŸ”Ή Weakness: Authentication Bypass
πŸ”Ή Reported To: AWS VDP
πŸ”Ή Reported By: notnotnotveg
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 22, 2026, 7:53pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Identity Theft via Broken Link Hijacking on NASA Astronaut News Release Page

πŸ”Ή Severity: Low
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: muhammadabdillah64edc3
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 22, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Arbitrary External Redirect Through SAML RelayState After Successful Authentication

πŸ”Ή Severity: Low
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: 2yuk
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 22, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Blind SQL Injection in Search Functionality Leads to Full Database Extraction

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: molany
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 22, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Exposed Credentials in Public .env File on NASA Git Repository

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: Hunt3rboy
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 22, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Critical Authentication Bypass via Path Normalization (Double Slash) on Live NASA MODAPS OKAPI Production Instance

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: marcelojr
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 22, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
RE : Host Header Injection leads to Cookie Domain Manipulation on sealevel.nasa.gov

πŸ”Ή Severity: Informational
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: sanjay910
πŸ”Ή State: βšͺ️ Informational
πŸ”Ή Disclosed: July 23, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Reflected XSS and HTML Injection on cce-signin.gsfc.nasa.gov via 'popup_flag' parameter

πŸ”Ή Severity: Low
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: ItsS4LEH
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 23, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report