Bugpoint
969 subscribers
3.91K photos
3.91K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Unauthenticated Path Traversal (LFI) via /custom-sounds/ when CustomSounds uses FileSystem storage

πŸ”Ή Severity: High
πŸ”Ή Weakness: Path Traversal
πŸ”Ή Reported To: Rocket.Chat
πŸ”Ή Reported By: howtoplay
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 3, 2026, 1:35pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
GitHub Retired UsernameTakeover From [aws/β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ]

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Inclusion of Functionality from Untrusted Control Sphere
πŸ”Ή Reported To: AWS VDP
πŸ”Ή Reported By: sh3d0w
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 3, 2026, 6:17pm (UTC)
🐞 Source: HackerOne

A retired GitHub username was discovered to be unclaimed, allowing an attacker to register the username and create a repository with the same name as the original. As a result, the original link to the repository now points to the attacker-controlled repository, enabling a persistent repository hijack.

πŸ‘‰ Read full report
Heap use-after-free (write) in mev_forget_socket() via reentrant curl_easy_pause() β€” incomplete fix for CVE-2026-9080

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Use After Free
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: juthawong
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: August 4, 2026, 2:55pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
`relay_tx` wallet-rpc skips `--restricted-rpc` guard and lets any caller corrupt wallet state via attacker-controlled `pending_tx`

πŸ”Ή Severity: Critical
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: benisprlh
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 5, 2026, 5:05am (UTC)
🐞 Source: HackerOne

The `relay_tx` wallet-RPC method in Monero was found to bypass the `--restricted-rpc` guard, allowing any caller to corrupt the wallet state by submitting a malicious `pending_tx` blob. The issue was that the `on_relay_tx` handler did not perform any ownership checks on the supplied `pending_tx` before passing it to `commit_tx`, which then updated the wallet state based on the attacker-controlled data. This…

πŸ‘‰ Read full report
wallet-rpc describe_transfer uses real_output_in_tx_index instead of real_output: cold-wallet pre-sign review shows wrong ring member

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Array Index Underflow
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: bebensap
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 5, 2026, 10:23am (UTC)
🐞 Source: HackerOne

The wallet-rpc method "describe_transfer" was found to use the wrong index when retrieving information about the ring members for each input. Instead of using the "real_output" index, which represents the position of the real entry in the ring, it used the "real_output_in_tx_index", which represents the position of the output in the source transaction. This resulted in the pre-sign review displaying the wrong…

πŸ‘‰ Read full report
SpendProofV1 txid-substitution: get_spend_proof/check_spend_proof do not verify returned transaction hash

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Missing Required Cryptographic Step
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: bebensap
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 5, 2026, 10:23am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the Monero project where the get_spend_proof and check_spend_proof functions do not verify the returned transaction hash against the requested transaction ID. This allows a malicious or compromised daemon to provide a valid serialized transaction body for a different transaction than the one requested, which can be used to create or verify a spend proof for that different…

πŸ‘‰ Read full report
wallet-rpc crash via malformed /gettransactions response (empty txs β†’ vector::front() in check_tx_key / check_tx_proof)

πŸ”Ή Severity: High
πŸ”Ή Weakness: NULL Pointer Dereference
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: bebensap
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 5, 2026, 10:23am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the Monero wallet software that could cause the wallet-rpc process to crash when handling a malformed response from the daemon's /gettransactions endpoint. The vulnerability was due to the wallet software making assumptions about the response structure that were not always valid, leading to undefined behavior when attempting to access empty data structures. The crash occurred when…

πŸ‘‰ Read full report
`check_reserve_proof` sums RingCT ECDH amounts without checking the output commitment

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Missing Required Cryptographic Step
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: bebensap
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 5, 2026, 10:23am (UTC)
🐞 Source: HackerOne

The `check_reserve_proof` function in the Monero codebase was found to sum RingCT ECDH amounts without checking the output commitment. The decoded amount was added to the total without verifying that it matched the commitment, which could allow a malicious prover to claim larger reserves than actually exist on-chain.

πŸ‘‰ Read full report
`check_reserve_proof` counts duplicate entries: one output can inflate `total`

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Business Logic Errors
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: bebensap
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 5, 2026, 10:23am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the `check_reserve_proof` function in the Monero wallet software. The vulnerability allowed duplicate entries in the reserve proof, which could artificially inflate the reported total reserve amount without affecting the verification of individual entries. The issue was in the verifier logic, where the accounting was done in a flat manner, adding the output amount for each row…

πŸ‘‰ Read full report
curl Missing Sec-WebSocket-Accept Verification Enables MITM WebSocket Session Hijacking

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Man-in-the-Middle
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: kiyin
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: August 5, 2026, 11:13am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Unauthenticated RCE in Taskcluster web-server via GraphQL filter argument (sift $where)

πŸ”Ή Severity: Critical | πŸ’° 12,000 USD
πŸ”Ή Weakness: Code Injection
πŸ”Ή Reported To: Mozilla
πŸ”Ή Reported By: griffinf
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 5, 2026, 3:50pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the Taskcluster web-server that allowed unauthenticated remote code execution through the GraphQL filter argument. The issue was caused by the use of the 'sift' library, which compiled the filter's '$where' string into a function using 'new Function' and executed it. This allowed an attacker to run arbitrary JavaScript in the context of the Node.js process, resulting in the…

πŸ‘‰ Read full report
[Wii U/3DS/Switch] Improper bounds check in StationURL in all NEX clients leading to remote crash/RCE

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Stack Overflow
πŸ”Ή Reported To: Nintendo
πŸ”Ή Reported By: jonbarrow
πŸ”Ή State: πŸ”΅ Duplicate
πŸ”Ή Disclosed: August 7, 2026, 1:04am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
URL API: triple-slash parses path segment as hostname

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Use of Incorrectly-Resolved Name or Reference
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: thinhlx
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: August 7, 2026, 8:49pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Adding phone number to profile By OTP brute forcing

πŸ”Ή Severity: Medium | πŸ’° 100 USD
πŸ”Ή Weakness: Insecure Storage of Sensitive Information
πŸ”Ή Reported To: CoinMate.io
πŸ”Ή Reported By: ganesh_reddy
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 8, 2026, 9:11am (UTC)
🐞 Source: HackerOne

A vulnerability was found that allowed an attacker to add any phone number to a user's profile by brute-forcing the one-time password (OTP) used for phone number verification. The steps involved intercepting the OTP verification request, using a brute-force attack to find the valid OTP, and then replaying the original request with the discovered OTP to complete the phone number addition.

πŸ‘‰ Read full report
Unauthenticated MQTT Wildcard (board/#) Leaks All Pinboard UUIDs to Unauthorized Users

πŸ”Ή Severity: High
πŸ”Ή Reported To: Opera Public Bug Bounty
πŸ”Ή Reported By: ty5ona
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 11, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Myndr CORS Misconfiguration

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: Myndr
πŸ”Ή Reported By: hackwithshubh
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2026, 6:22am (UTC)
🐞 Source: HackerOne

The CORS configuration on admin.myndr.net allowed any .myndr.net subdomain to read authenticated admin panel responses, including CSRF nonces and session data. This vulnerability could have been exploited to take over admin accounts.

πŸ‘‰ Read full report
JaaS: Unauthenticated, cross-tenant outbound SIP calling via JaaS SIP gateway (toll fraud + caller-ID spoofing)

πŸ”Ή Severity: Medium | πŸ’° 500 USD
πŸ”Ή Weakness: Missing Authorization
πŸ”Ή Reported To: 8x8
πŸ”Ή Reported By: offseq
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2026, 4:07pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the JaaS SIP gateway that allowed unauthenticated, cross-tenant outbound SIP calling. This could have facilitated toll fraud and caller-ID spoofing.

πŸ‘‰ Read full report
Reflected XSS on itims.bia.gov

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Bureau of Indian Affairs
πŸ”Ή Reported By: meeterpreeter
πŸ”Ή State: 🟠 Unresolved
πŸ”Ή Disclosed: August 13, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Host Header Injection

πŸ”Ή Severity: Informational
πŸ”Ή Reported To: Bureau of Indian Affairs
πŸ”Ή Reported By: ChinmayNangia
πŸ”Ή State: βšͺ️ Informational
πŸ”Ή Disclosed: August 13, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Server Side Errors

πŸ”Ή Severity: Informational
πŸ”Ή Reported To: The Bureau of Indian Education Vulnerability Disclosure Program
πŸ”Ή Reported By: mrnazu01
πŸ”Ή State: βšͺ️ Informational
πŸ”Ή Disclosed: August 13, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Debug Deep Link Abuse Allows Repeated Forced Logout and Application Disruption

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Violation of Secure Design Principles
πŸ”Ή Reported To: Yelp
πŸ”Ή Reported By: 0xkarim_dix
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2026, 1:30pm (UTC)
🐞 Source: HackerOne

A debug deep link was discovered in the Android application "com.yelp.android.biz" that could be triggered externally, causing the application to crash and the user's session to be invalidated, requiring the user to log in again. The existence of this exposed deep link allowed any malicious application installed on the same device to repeatedly trigger this behavior, resulting in a persistent local denial of…

πŸ‘‰ Read full report