Bugpoint
969 subscribers
3.91K photos
3.91K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Reflected XSS on itims.bia.gov

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Bureau of Indian Affairs
πŸ”Ή Reported By: meeterpreeter
πŸ”Ή State: 🟠 Unresolved
πŸ”Ή Disclosed: August 13, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Host Header Injection

πŸ”Ή Severity: Informational
πŸ”Ή Reported To: Bureau of Indian Affairs
πŸ”Ή Reported By: ChinmayNangia
πŸ”Ή State: βšͺ️ Informational
πŸ”Ή Disclosed: August 13, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Server Side Errors

πŸ”Ή Severity: Informational
πŸ”Ή Reported To: The Bureau of Indian Education Vulnerability Disclosure Program
πŸ”Ή Reported By: mrnazu01
πŸ”Ή State: βšͺ️ Informational
πŸ”Ή Disclosed: August 13, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Debug Deep Link Abuse Allows Repeated Forced Logout and Application Disruption

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Violation of Secure Design Principles
πŸ”Ή Reported To: Yelp
πŸ”Ή Reported By: 0xkarim_dix
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2026, 1:30pm (UTC)
🐞 Source: HackerOne

A debug deep link was discovered in the Android application "com.yelp.android.biz" that could be triggered externally, causing the application to crash and the user's session to be invalidated, requiring the user to log in again. The existence of this exposed deep link allowed any malicious application installed on the same device to repeatedly trigger this behavior, resulting in a persistent local denial of…

πŸ‘‰ Read full report
Cookie jar load skips public suffix check on PSL builds

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Information Exposure Through Sent Data
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: 1rhino2
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 14, 2026, 7:33am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
libcurl cache updates follow symlinks and truncate their targets

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Time-of-check Time-of-use (TOCTOU) Race Condition
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: mr4bugs
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: August 14, 2026, 12:04pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Windows SSPI connection-pool probe can reuse a connection under the wrong user

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Authentication Bypass by Spoofing
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: mr4bugs
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: August 14, 2026, 12:05pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
TaskProcessing callback authorization bypass allows ex-members to post as Assistant Talk Bot

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Insecure Direct Object Reference (IDOR)
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: kuninogu
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 14, 2026, 2:50pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered that allowed an authenticated low-privilege user to cause the trusted Assistant Talk Bot to post attacker-guided AI-generated content into a Talk conversation, even after the user had left the conversation. The issue was caused by the Talk Bot's endpoint trusting the caller-supplied conversation token without verifying that the callback belonged to a task originally scheduled by the…

πŸ‘‰ Read full report
`set_daemon` wallet-rpc silently ignores `ssl_allowed_fingerprints` β†’ pinning bypassed, wallet↔daemon MITM

πŸ”Ή Severity: High
πŸ”Ή Weakness: Improper Certificate Validation
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: benisprlh
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 5, 2026, 5:06am (UTC)
🐞 Source: HackerOne

The `set_daemon` JSON-RPC in `monero-wallet-rpc` was found to have a vulnerability that silently ignored the `ssl_allowed_fingerprints` parameter, allowing MITM attacks against the wallet-daemon connection. The vulnerability was introduced in the initial release of the RPC in March 2019 and affected all subsequent versions up to the latest release. The vulnerability was caused by improper handling of the…

πŸ‘‰ Read full report
Restricted RPC Policy Bypass on ZMQ JSON-RPC Allows Unauthenticated Remote Admin Actions

πŸ”Ή Severity: High
πŸ”Ή Weakness: Improper Authentication - Generic
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: usagirabbit
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 17, 2026, 9:16am (UTC)
🐞 Source: HackerOne

A high-severity access-control issue was found in Monero's ZMQ JSON-RPC surface. When the daemon is started in restricted/public-node mode, the HTTP RPC layer correctly suppresses admin-only methods, but the ZMQ JSON-RPC layer did not inherit or enforce that restriction. This allowed an unauthenticated remote client to invoke state-changing methods that should have been unavailable in restricted mode.

πŸ‘‰ Read full report
Wallet RPC Restricted-Mode Policy Bypass

πŸ”Ή Severity: High
πŸ”Ή Weakness: Improper Authentication - Generic
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: usagirabbit
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 17, 2026, 9:16am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the Monero wallet RPC server that allowed restricted-mode clients to perform non-view-only operations. The issue was caused by inconsistent enforcement of the restricted mode, which allowed clients to bypass the intended view-only access controls and perform state-changing actions such as creating wallets, closing wallets, and mutating wallet state. The vulnerability was confirmed…

πŸ‘‰ Read full report
URGENT: CRITICAL DATA BREACH - Cross-User PHI/PII Leakage via Prompt Injection - Non-malicious discovery

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: OpenAI
πŸ”Ή Reported By: Teringette-adamuzonyi
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 19, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Stored HTML Injection (CWE-79) via Livechat Visitor Name

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Cross-site Scripting (XSS) - DOM
πŸ”Ή Reported To: Rocket.Chat
πŸ”Ή Reported By: hillng
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2026, 7:18pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
DDP methods getThreadsList / getThreadMessages leaks private thread content to any authenticated low privilege user (unpatched sibling of #1446767)

πŸ”Ή Severity: High
πŸ”Ή Weakness: NoSQL Injection
πŸ”Ή Reported To: Rocket.Chat
πŸ”Ή Reported By: iamaangx028
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2026, 7:54pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Unauthenticated Error-Based SQL Injection via POST Parameter Name in /api/experiment/answer/new/

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: iaramsri
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Unauthenticated Remote Code Execution in NASA AMMOS AIT-GUI 2.5.0 via /tlm/query file write chained to /script/run code execution

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: ward0
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Unauthenticated SSRF in NASA Trek addManifest allows internal network access from the Trek server

πŸ”Ή Severity: High
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: n0RollBack
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Unauthorized Access to CI/CD Infrastructure and Project Secrets via Compromised GitLab Runner Token

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: oguzhan_00
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Loss of multisig funds through single malicious participant's deliberate deception

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Business Logic Errors
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: k-privacy-enjoyer
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2026, 11:47pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the Monero multisig implementation. A single malicious participant of a multisig could trick other users into sending funds multiple times to a certain recipient, which could not be easily distinguished from a legitimate user action. This issue was caused by the inability to view the inputs of partially signed multisig transactions, and the lack of a mechanism to deliberately…

πŸ‘‰ Read full report
monero:// deeplink parsing accepts tx_amount=(all) and can trigger send-all transaction mode

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Business Logic Errors
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: qttps
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2026, 11:47pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the Monero GUI wallet application. The vulnerability allowed an attacker to craft a malicious URI that could be used to trigger a "send-all" transaction mode, where the victim's entire unlocked balance would be transferred to the attacker's address. The vulnerability was caused by improper validation of the "tx_amount" parameter in the external "monero://" URI handler, which…

πŸ‘‰ Read full report
Windows installer grants low-privileged users write access to executable P2Pool directory, enabling local code execution

πŸ”Ή Severity: High
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: qttps
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2026, 11:47pm (UTC)
🐞 Source: HackerOne

A Windows installer for the Monero GUI wallet created a subdirectory for P2Pool with overly broad write permissions for low-privileged users. The GUI later executed the `p2pool.exe` binary from that directory without any additional integrity checks, allowing a local attacker to plant malicious code that would be executed by the GUI.

πŸ‘‰ Read full report