Bugpoint
969 subscribers
3.92K photos
3.92K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
GitHub user to server tokens can create issues in any public repository

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: GitHub
πŸ”Ή Reported By: ahacker1
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 22, 2026, 7:39pm (UTC)
🐞 Source: HackerOne

A vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope. The authorization check only verified that the installation had read permissions on the target repository rather than verifying that the token's installation was explicitly granted access to…

πŸ‘‰ Read full report
AWS *.a2z.com | Unauthenticated Clickhouse UI : Database access + SSRF

πŸ”Ή Severity: High
πŸ”Ή Weakness: Authentication Bypass
πŸ”Ή Reported To: AWS VDP
πŸ”Ή Reported By: notnotnotveg
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 22, 2026, 7:53pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Identity Theft via Broken Link Hijacking on NASA Astronaut News Release Page

πŸ”Ή Severity: Low
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: muhammadabdillah64edc3
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 22, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Arbitrary External Redirect Through SAML RelayState After Successful Authentication

πŸ”Ή Severity: Low
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: 2yuk
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 22, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Blind SQL Injection in Search Functionality Leads to Full Database Extraction

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: molany
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 22, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Exposed Credentials in Public .env File on NASA Git Repository

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: Hunt3rboy
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 22, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Critical Authentication Bypass via Path Normalization (Double Slash) on Live NASA MODAPS OKAPI Production Instance

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: marcelojr
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 22, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
RE : Host Header Injection leads to Cookie Domain Manipulation on sealevel.nasa.gov

πŸ”Ή Severity: Informational
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: sanjay910
πŸ”Ή State: βšͺ️ Informational
πŸ”Ή Disclosed: July 23, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Reflected XSS and HTML Injection on cce-signin.gsfc.nasa.gov via 'popup_flag' parameter

πŸ”Ή Severity: Low
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: ItsS4LEH
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 23, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Data-Sculptor CSV expression evaluation leads to backend RCE, Kubernetes serviceaccount token disclosure, and authenticated Kubernetes control-plane access

πŸ”Ή Severity: High
πŸ”Ή Reported To: Atlassian
πŸ”Ή Reported By: MononcleMich
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 23, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
ZMQ RPC Log Injection and Untrusted Payload Persistence

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: CRLF Injection
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: redlobsterzzz
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 24, 2026, 7:19pm (UTC)
🐞 Source: HackerOne

A vulnerability was reported in the Monero CLI daemon where the ZMQ RPC request path logs untrusted request content before semantic validation. This allowed a remote party with access to the ZMQ endpoint to inject newline and control-character content into daemon logs, enabling log forging. The vulnerability was introduced in commit 77986023c3 and affected releases from v0.12.0.0 through v0.18.4.6, as well as the…

πŸ‘‰ Read full report
Authentication Bypass via XML Signature Wrapping in SAML SSO

πŸ”Ή Severity: Critical
πŸ”Ή Weakness: Improper Authentication - Generic
πŸ”Ή Reported To: Rocket.Chat
πŸ”Ή Reported By: 0jayden
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 27, 2026, 4:37pm (UTC)
🐞 Source: HackerOne

The SAML SSO implementation in Rocket.Chat verified XML signatures but did not bind the validated signature to the `samlp:Response` or `saml:Assertion`. As a result, an attacker could submit a wrapped document carrying forged identity attributes alongside a valid signature made by the trusted IdP certificate, and gain unauthorized access to the system.

πŸ‘‰ Read full report
Non-Production API Endpoints for the Amazon Cloudwatch Fails to Log to CloudTrail Resulting in Silent Permission Enumeration

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Insufficient Logging
πŸ”Ή Reported To: AWS VDP
πŸ”Ή Reported By: nick_frichette_dd
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 27, 2026, 7:51pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the Amazon CloudWatch service, where certain non-production API endpoints could be used to perform permission enumeration without generating corresponding CloudTrail events. This allowed for silent testing of compromised IAM credentials. The vulnerability was reported to AWS, which acknowledged it as a security issue. Specific endpoints and operations that exhibited this behavior…

πŸ‘‰ Read full report
Sandbox User Can Inject Rogue CA Certificate into OS Trust Store via Sudo-Allowed deploy-certificates.sh

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Improper Certificate Validation
πŸ”Ή Reported To: AWS VDP
πŸ”Ή Reported By: mistercloudsec
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 28, 2026, 3:29pm (UTC)
🐞 Source: HackerOne

A vulnerability was found in the Bedrock AgentCore Code Interpreter sandbox. The sandbox granted a user passwordless sudo access to a script that deployed certificates to the OS trust store. An attacker could have generated a rogue CA certificate, placed it in a writable directory, and then used the sudo-allowed script to inject the rogue CA into the trust store. This could have been used to perform…

πŸ‘‰ Read full report
Unauthenticated SSRF in Voxtelesys integration ('checkUrlForSsrf' Bypass via DNS rebinding)

πŸ”Ή Severity: High
πŸ”Ή Weakness: Server-Side Request Forgery (SSRF)
πŸ”Ή Reported To: Rocket.Chat
πŸ”Ή Reported By: button142857
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 29, 2026, 1:48am (UTC)
🐞 Source: HackerOne

An SSRF vulnerability was discovered in Rocket.Chat version 7.13.2 that was caused by a DNS rebinding attack. The vulnerability allowed an attacker to bypass a security check and access internal hosts on the same network as the Rocket.Chat server. The vulnerability was present in the SMS integration feature that used the `checkUrlForSsrf` function, which was bypassed by the DNS rebinding attack.

πŸ‘‰ Read full report
Permission Model Bypass: `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: Node.js
πŸ”Ή Reported By: 0xoroot
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 29, 2026, 2:16pm (UTC)
🐞 Source: HackerOne

A flaw in Node.js Permission Model enforcement was discovered that allowed `trace_events.createTracing().enable()` to write trace logs outside of the `--allow-fs-write` setting. This vulnerability affected Node.js versions 22.x, 24.x, and 26.x.

πŸ‘‰ Read full report
HTTPS Agent PFX object-array key collision allows mTLS client identity reuse across different per-request certificates

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Improper Authentication - Generic
πŸ”Ή Reported To: Node.js
πŸ”Ή Reported By: yottt
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 29, 2026, 2:45pm (UTC)
🐞 Source: HackerOne

A flaw in Node.js HTTPS Agent connection reuse was discovered that could cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affected Node.js versions 26.x, 24.x, and 22.x.

πŸ‘‰ Read full report
`exportReportPdf` mutation shows internal Activity

πŸ”Ή Severity: High
πŸ”Ή Reported To: HackerOne
πŸ”Ή Reported By: 0v3rw4tch
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 29, 2026, 3:01pm (UTC)
🐞 Source: HackerOne

A vulnerability was identified in the PDF export path for disclosed reports. When a report was exported to PDF, the export pipeline did not apply the same visibility and authorization scoping that governs the normal report view. The root cause was that PDF generation assembled report content from the underlying timeline without re-checking each activity against the requester's permission level. The issue was…

πŸ‘‰ Read full report
Permission Model: --allow-fs-read/--allow-fs-write radix-tree prefix-boundary over-grant

πŸ”Ή Severity: High
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: Node.js
πŸ”Ή Reported By: sy2n0
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 29, 2026, 11:00pm (UTC)
🐞 Source: HackerOne

A flaw was discovered in the Node.js Permission Model's enforcement of filesystem access control. The vulnerability could allow an attacker granted access to one path to read from or write to paths outside the intended filesystem allowlist, due to issues with the radix-tree prefix-boundary handling. This affected Node.js versions in the main, 22.x, 24.x, and 26.x branches.

πŸ‘‰ Read full report
GitHub scoped user to server tokens can escape their installation

πŸ”Ή Severity: High
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: GitHub
πŸ”Ή Reported By: ahacker1
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 29, 2026, 11:35pm (UTC)
🐞 Source: HackerOne

An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server was discovered. The vulnerability allowed an authenticated attacker to access private repositories outside the intended installation scope, which could have included write operations, via an authorization fallback that treated a revoked/deleted installation as a global installation context. This…

πŸ‘‰ Read full report
HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934)

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Exploiting Incorrectly Configured SSL/TLS
πŸ”Ή Reported To: Node.js
πŸ”Ή Reported By: vnyuh
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 30, 2026, 2:09am (UTC)
🐞 Source: HackerOne

A vulnerability was identified in Node.js where HTTPS Agent TLS session reuse skipped hostname verification across identity policies, which was an incomplete fix for CVE-2026-48934. This affected Node.js versions 22.x, 24.x, and 26.x.

πŸ‘‰ Read full report