Bugpoint
969 subscribers
3.92K photos
3.92K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Unauthenticated Remote Code Execution in NASA AMMOS AIT-GUI 2.5.0 via /tlm/query file write chained to /script/run code execution

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: ward0
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Unauthenticated SSRF in NASA Trek addManifest allows internal network access from the Trek server

πŸ”Ή Severity: High
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: n0RollBack
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Unauthorized Access to CI/CD Infrastructure and Project Secrets via Compromised GitLab Runner Token

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: oguzhan_00
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Loss of multisig funds through single malicious participant's deliberate deception

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Business Logic Errors
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: k-privacy-enjoyer
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2026, 11:47pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the Monero multisig implementation. A single malicious participant of a multisig could trick other users into sending funds multiple times to a certain recipient, which could not be easily distinguished from a legitimate user action. This issue was caused by the inability to view the inputs of partially signed multisig transactions, and the lack of a mechanism to deliberately…

πŸ‘‰ Read full report
monero:// deeplink parsing accepts tx_amount=(all) and can trigger send-all transaction mode

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Business Logic Errors
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: qttps
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2026, 11:47pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the Monero GUI wallet application. The vulnerability allowed an attacker to craft a malicious URI that could be used to trigger a "send-all" transaction mode, where the victim's entire unlocked balance would be transferred to the attacker's address. The vulnerability was caused by improper validation of the "tx_amount" parameter in the external "monero://" URI handler, which…

πŸ‘‰ Read full report
Windows installer grants low-privileged users write access to executable P2Pool directory, enabling local code execution

πŸ”Ή Severity: High
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: qttps
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2026, 11:47pm (UTC)
🐞 Source: HackerOne

A Windows installer for the Monero GUI wallet created a subdirectory for P2Pool with overly broad write permissions for low-privileged users. The GUI later executed the `p2pool.exe` binary from that directory without any additional integrity checks, allowing a local attacker to plant malicious code that would be executed by the GUI.

πŸ‘‰ Read full report
HTML Injection in Transaction Confirmation Dialog via Address Book Description Enables UI Spoofing Before Fund Transfer

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Code Injection
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: fg0x0
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2026, 11:49pm (UTC)
🐞 Source: HackerOne

The Monero GUI wallet was found to render address book descriptions as HTML in the transaction confirmation dialog without sanitizing the input. This vulnerability could enable an attacker to craft a malicious Monero URI or QR code, which when added to the victim's address book, would display arbitrary HTML in the confirmation dialog before fund transfer. This could be used to spoof the recipient's details and…

πŸ‘‰ Read full report
View-only offline transaction creation bypasses the long-payment-ID privacy block

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Information Disclosure
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: qttps
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2026, 11:49pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the monero-gui wallet software where the view-only offline transaction creation process did not enforce the same protection against long payment IDs as the normal online transaction sending process. This allowed a malicious payment request to include a standalone payment ID, which could then be included in an unsigned offline transaction, potentially exposing the user's transaction…

πŸ‘‰ Read full report
Monero GUI OpenAlias DNSSEC-invalid resolution still writes spoofable address into recipient field

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Monero
πŸ”Ή Reported By: lilpeko
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2026, 11:51pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the Monero GUI that could allow an attacker to spoof the recipient address for a transaction. The vulnerability was caused by the GUI writing a potentially spoofed address to the recipient field, even when DNSSEC validation failed during an OpenAlias resolution. This could result in funds being sent to an attacker-controlled address if the user proceeded with the transaction.

πŸ‘‰ Read full report
Domainless COOKIEFILE cookie leaks to unrelated IP-literal hosts

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Information Exposure Through Sent Data
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: accl
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 21, 2026, 6:32am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Path Traversal in Nextcloud Talk Android Exposes User Credentials and Private Data via FileProvider

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Path Traversal
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: mirachael
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2026, 1:23am (UTC)
🐞 Source: HackerOne

A vulnerability in Nextcloud Talk Android allowed an external Android app to write and retrieve config files by pinging an internal endpoint.

πŸ‘‰ Read full report
URI scheme validation bypass in ActionText `to_markdown` via user-supplied `<action-text-markdown>` marker tag

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Cross-site Scripting (XSS) - Reflected
πŸ”Ή Reported To: Ruby on Rails
πŸ”Ή Reported By: offsetmd
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2026, 4:21pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
wolfSSL backend disables hostname verification when CURLOPT_SSL_VERIFYPEER is 0

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Improper Validation of Certificate with Host Mismatch
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: subadevan
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: August 24, 2026, 9:51pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
RTSP CRLF injection in libcurl allows CURLOPT_RTSP_* values to inject commands into independent sessions

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: CRLF Injection
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: subadevan
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: August 24, 2026, 9:51pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
@jitsi/docker-jitsi-meet: `/colibri-relay-ws/` unsafe nginx regex (OCTO relay configuration)

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Cross-site Scripting (XSS) - Generic
πŸ”Ή Reported To: 8x8
πŸ”Ή Reported By: a3z4km3
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 25, 2026, 2:09am (UTC)
🐞 Source: HackerOne

An unsafe nginx regex pattern was discovered in the `/colibri-relay-ws/` location of the @jitsi/docker-jitsi-meet project. The regex `[a-zA-Z0-9-\\._]+` accepted arbitrary domain names and IP addresses for proxy_pass directives, allowing unauthenticated requests to be proxied to attacker-specified destinations. The vulnerable nginx location and associated relay WebSocket proxy configuration have been removed.

πŸ‘‰ Read full report
libcurl Digest/NTLM authentication ignores an explicit Authorization header

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Incorrect Authorization
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: subadevan
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 25, 2026, 1:26pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
TLS session cache case-folds CA paths and bypasses the active trust profile

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Improper Certificate Validation
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: 1rhino2
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 25, 2026, 5:21pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Add labels to arbitrary issues/prs via Memex Bulk Update to compromise github actions label gating

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Insecure Direct Object Reference (IDOR)
πŸ”Ή Reported To: GitHub
πŸ”Ή Reported By: ahacker1
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 25, 2026, 9:22pm (UTC)
🐞 Source: HackerOne

A vulnerability was identified in GitHub Enterprise Server that allowed a user with read access to a repository and write access to a project to modify issue and pull request metadata through the project. When adding an item to a project that already existed, column value updates were applied without verifying the actor's repository write permissions.

πŸ‘‰ Read full report
Hidden/restricted tags can be mutated through synonym ID paths without per-tag authorization

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Insecure Direct Object Reference (IDOR)
πŸ”Ή Reported To: Discourse
πŸ”Ή Reported By: ahpuh
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2026, 5:47am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in Discourse where a non-admin user with tag-editing permission could modify hidden or restricted tags by supplying their numeric IDs to the synonym creation and tag settings endpoints. Although the user could not view the hidden tags, the controller only authorized the visible target tag and did not re-check authorization for each synonym tag ID, allowing the non-admin user to update…

πŸ‘‰ Read full report
curl_share TOCTOU > RCE via Curl_llist _dtor Function Pointer Hijack

πŸ”Ή Severity: Critical
πŸ”Ή Weakness: Time-of-check Time-of-use (TOCTOU) Race Condition
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: k4rasu_s4ma
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: August 26, 2026, 6:38am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Critical SQL Injection WDM API (β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ)

πŸ”Ή Severity: Critical
πŸ”Ή Weakness: SQL Injection
πŸ”Ή Reported To: Essity
πŸ”Ή Reported By: matty69v
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2026, 7:23am (UTC)
🐞 Source: HackerOne

A boolean-based and time-based blind SQL injection vulnerability was discovered in the searchText query parameter of the GET /api/WDMProduct endpoint. The vulnerability allowed an unauthenticated attacker to read or modify data in the backing Microsoft SQL Server database. The backend was found to be hosted on an Azure App Service and served by the in-scope Angular front-end application.

πŸ‘‰ Read full report