π― New Report #3031518: CVE-2025-24813: Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet
πΊSeverity: High
π½ Reporter: sw0rd1ight
πΌ Team: Internet Bug Bounty
π΅ Bounty: 4323
π Submitted: 2025-03-11
β° Disclosed: 2025-04-27 14:53:24
π Summary: The Apache Tomcat vulnerability CVE-2025-24813 allowed remote code execution and information disclosure. The vulnerability was caused by a combination of features, including writes enabled for the default servlet, support for partial PUT requests, and the use of Tomcat's file-based session persistence with the default storage location. If these conditions were met, a malicious user could have taken advantage of the vulnerability.
@hackeronereports
πΊSeverity: High
π½ Reporter: sw0rd1ight
πΌ Team: Internet Bug Bounty
π΅ Bounty: 4323
π Submitted: 2025-03-11
β° Disclosed: 2025-04-27 14:53:24
π Summary: The Apache Tomcat vulnerability CVE-2025-24813 allowed remote code execution and information disclosure. The vulnerability was caused by a combination of features, including writes enabled for the default servlet, support for partial PUT requests, and the use of Tomcat's file-based session persistence with the default storage location. If these conditions were met, a malicious user could have taken advantage of the vulnerability.
@hackeronereports
π― New Report #3013913: [CVE-2025-27219 Denial of Service in CGI::Cookie.parse](https://hackerone.com/reports/3013913)
πΊSeverity: Medium
π½ Reporter: lio346
πΌ Team: Internet Bug Bounty
π΅ Bounty: null
π Submitted: 2025-02-26
β° Disclosed: 2025-04-27 14:27:52
π Summary: A denial-of-service vulnerability was discovered in the
@hackeronereports
πΊSeverity: Medium
π½ Reporter: lio346
πΌ Team: Internet Bug Bounty
π΅ Bounty: null
π Submitted: 2025-02-26
β° Disclosed: 2025-04-27 14:27:52
π Summary: A denial-of-service vulnerability was discovered in the
CGI::Cookie.parse method of the Ruby cgi gem. The vulnerability was caused by the method taking super-linear time to parse a maliciously crafted cookie string. This could have led to service disruptions. The vulnerability was assigned the CVE identifier CVE-2025-27219.@hackeronereports
π― New Report #3094406: Heapβbased buffer overflow in curl -K <config file> allows arbitrary write .
πΊSeverity: High
π½ Reporter: bsr13
πΌ Team: curl
π΅ Bounty: null
π Submitted: 2025-04-15
β° Disclosed: 2025-04-27 16:00:11
π Summary: null
@hackeronereports
πΊSeverity: High
π½ Reporter: bsr13
πΌ Team: curl
π΅ Bounty: null
π Submitted: 2025-04-15
β° Disclosed: 2025-04-27 16:00:11
π Summary: null
@hackeronereports
π― New Report #3002543: CVE-2024-43398: DoS vulnerability in REXML
πΊSeverity: Low
π½ Reporter: l33thaxor
πΌ Team: Internet Bug Bounty
π΅ Bounty: 505
π Submitted: 2025-02-19
β° Disclosed: 2025-04-27 16:57:59
π Summary: The CVE-2024-43398 vulnerability was a denial-of-service issue in the REXML library due to poor performance when parsing specially crafted XML. This vulnerability was addressed with a patch released by the Ruby team.
@hackeronereports
πΊSeverity: Low
π½ Reporter: l33thaxor
πΌ Team: Internet Bug Bounty
π΅ Bounty: 505
π Submitted: 2025-02-19
β° Disclosed: 2025-04-27 16:57:59
π Summary: The CVE-2024-43398 vulnerability was a denial-of-service issue in the REXML library due to poor performance when parsing specially crafted XML. This vulnerability was addressed with a patch released by the Ruby team.
@hackeronereports
π― New Report #3082917: Possible Sensitive Session Information Leak in Active Storage
πΊSeverity: High
π½ Reporter: tyage
πΌ Team: Internet Bug Bounty
π΅ Bounty: 4323
π Submitted: 2025-04-08
β° Disclosed: 2025-04-27 22:55:36
π Summary: There was a possible sensitive session information leak in Active Storage. Active Storage incorrectly sent the user's session cookie along with a Cache-Control: public header when serving files (blobs). This allowed certain caching proxies to cache the response, including the Set-Cookie header, potentially exposing the original user's session cookie to unrelated users.
@hackeronereports
πΊSeverity: High
π½ Reporter: tyage
πΌ Team: Internet Bug Bounty
π΅ Bounty: 4323
π Submitted: 2025-04-08
β° Disclosed: 2025-04-27 22:55:36
π Summary: There was a possible sensitive session information leak in Active Storage. Active Storage incorrectly sent the user's session cookie along with a Cache-Control: public header when serving files (blobs). This allowed certain caching proxies to cache the response, including the Set-Cookie header, potentially exposing the original user's session cookie to unrelated users.
@hackeronereports
π― New Report #3103849: Privilege Escalation leads to Unauthorized Access to Private Conversations By any Regular user [Read , Edit and Delete](https://hackerone.com/reports/3103849)
πΊSeverity: Critical
π½ Reporter: 0xsom3a
πΌ Team: Dust
π΅ Bounty: null
π Submitted: 2025-04-22
β° Disclosed: 2025-04-29 11:01:20
π Summary: null
@hackeronereports
πΊSeverity: Critical
π½ Reporter: 0xsom3a
πΌ Team: Dust
π΅ Bounty: null
π Submitted: 2025-04-22
β° Disclosed: 2025-04-29 11:01:20
π Summary: null
@hackeronereports
π― New Report #3102890: User Limit Bypass via Pending Invitations in Workspace System
πΊSeverity: Medium
π½ Reporter: qatada
πΌ Team: Dust
π΅ Bounty: null
π Submitted: 2025-04-21
β° Disclosed: 2025-04-29 10:21:07
π Summary: The platform's workspace user limit was found to be vulnerable to bypass through the use of pending invitations. Users were able to join a workspace by signing up with an invited email, even after the workspace had reached its user limit for the current subscription tier. This allowed an unlimited number of users to be added to a restricted workspace, potentially impacting the platform's revenue model.
@hackeronereports
πΊSeverity: Medium
π½ Reporter: qatada
πΌ Team: Dust
π΅ Bounty: null
π Submitted: 2025-04-21
β° Disclosed: 2025-04-29 10:21:07
π Summary: The platform's workspace user limit was found to be vulnerable to bypass through the use of pending invitations. Users were able to join a workspace by signing up with an invited email, even after the workspace had reached its user limit for the current subscription tier. This allowed an unlimited number of users to be added to a restricted workspace, potentially impacting the platform's revenue model.
@hackeronereports
π― New Report #3104355: Race Condition in Folder Creation Allows Bypassing Folder Limit
πΊSeverity: Medium
π½ Reporter: 0xsom3a
πΌ Team: Dust
π΅ Bounty: null
π Submitted: 2025-04-22
β° Disclosed: 2025-04-29 10:17:40
π Summary: The application enforced a hard limit of 10 folders per user under a specific space. However, due to a race condition, it was possible to bypass this limit by sending multiple folder creation requests simultaneously after deleting one folder. This allowed creating more than 10 folders, breaking the intended restriction.
@hackeronereports
πΊSeverity: Medium
π½ Reporter: 0xsom3a
πΌ Team: Dust
π΅ Bounty: null
π Submitted: 2025-04-22
β° Disclosed: 2025-04-29 10:17:40
π Summary: The application enforced a hard limit of 10 folders per user under a specific space. However, due to a race condition, it was possible to bypass this limit by sending multiple folder creation requests simultaneously after deleting one folder. This allowed creating more than 10 folders, breaking the intended restriction.
@hackeronereports
π― New Report #3114132: Broken Access Control Exposes Email Verification Status and Privacy Settings via API Endpoint
πΊSeverity: Low
π½ Reporter: ctrl cipher
πΌ Team: WakaTime
π΅ Bounty: null
π Submitted: 2025-04-26
β° Disclosed: 2025-04-29 12:45:03
π Summary: The /api/v1/users/{username} endpoint leaked sensitive email-related metadata, such as the user's email confirmation status and privacy settings, without proper authorization checks. This allowed attackers to determine whether an account's email address was confirmed and the user's email privacy preferences, even if the email itself was hidden.
@hackeronereports
πΊSeverity: Low
π½ Reporter: ctrl cipher
πΌ Team: WakaTime
π΅ Bounty: null
π Submitted: 2025-04-26
β° Disclosed: 2025-04-29 12:45:03
π Summary: The /api/v1/users/{username} endpoint leaked sensitive email-related metadata, such as the user's email confirmation status and privacy settings, without proper authorization checks. This allowed attackers to determine whether an account's email address was confirmed and the user's email privacy preferences, even if the email itself was hidden.
@hackeronereports
π― New Report #3051155: Information disclosure on IBM training service endpoint
πΊSeverity: null
π½ Reporter: thpless
πΌ Team: IBM
π΅ Bounty: null
π Submitted: 2025-04-09
β° Disclosed: 2025-04-29 14:57:05
π Summary: The IBM training service endpoint had an information disclosure vulnerability that was reported to IBM, analyzed, and remediated. The vulnerability was discovered and reported by an external researcher.
@hackeronereports
πΊSeverity: null
π½ Reporter: thpless
πΌ Team: IBM
π΅ Bounty: null
π Submitted: 2025-04-09
β° Disclosed: 2025-04-29 14:57:05
π Summary: The IBM training service endpoint had an information disclosure vulnerability that was reported to IBM, analyzed, and remediated. The vulnerability was discovered and reported by an external researcher.
@hackeronereports
π― New Report #3117697: Double Free Vulnerability in `libcurl` Cookie Management (`cookie.c`)
πΊSeverity: null
π½ Reporter: tannicarcher
πΌ Team: curl
π΅ Bounty: null
π Submitted: 2025-04-29
β° Disclosed: 2025-04-29 21:16:18
π Summary: null
@hackeronereports
πΊSeverity: null
π½ Reporter: tannicarcher
πΌ Team: curl
π΅ Bounty: null
π Submitted: 2025-04-29
β° Disclosed: 2025-04-29 21:16:18
π Summary: null
@hackeronereports
π― New Report #3116935: Use of a Broken or Risky Cryptographic Algorithm (CWE-327) in libcurl
πΊSeverity: null
π½ Reporter: tannicarcher
πΌ Team: curl
π΅ Bounty: null
π Submitted: 2025-04-29
β° Disclosed: 2025-04-29 21:16:05
π Summary: null
@hackeronereports
πΊSeverity: null
π½ Reporter: tannicarcher
πΌ Team: curl
π΅ Bounty: null
π Submitted: 2025-04-29
β° Disclosed: 2025-04-29 21:16:05
π Summary: null
@hackeronereports
π― New Report #3114554: Privilege Persistence via Cloned Agent
πΊSeverity: Medium
π½ Reporter: yoyomiski
πΌ Team: Dust
π΅ Bounty: null
π Submitted: 2025-04-27
β° Disclosed: 2025-04-30 07:07:43
π Summary: The vulnerability allowed a member to clone an agent managed by the admin by modifying the agent's unique identifier (sid). This resulted in the admin being unable to effectively disable the agent, as the cloned version could still be used by the member even after the original agent was disabled.
@hackeronereports
πΊSeverity: Medium
π½ Reporter: yoyomiski
πΌ Team: Dust
π΅ Bounty: null
π Submitted: 2025-04-27
β° Disclosed: 2025-04-30 07:07:43
π Summary: The vulnerability allowed a member to clone an agent managed by the admin by modifying the agent's unique identifier (sid). This resulted in the admin being unable to effectively disable the agent, as the cloned version could still be used by the member even after the original agent was disabled.
@hackeronereports
π― New Report #3120790: Session Replay Attack Allows Authentication Bypass via Captured Login Responses Allowing Bypass of 429 Too many attempts for Multiple Failed Logins
πΊSeverity: High
π½ Reporter: ctrl cipher
πΌ Team: WakaTime
π΅ Bounty: null
π Submitted: 2025-05-01
β° Disclosed: 2025-05-01 19:33:10
π Summary: null
@hackeronereports
πΊSeverity: High
π½ Reporter: ctrl cipher
πΌ Team: WakaTime
π΅ Bounty: null
π Submitted: 2025-05-01
β° Disclosed: 2025-05-01 19:33:10
π Summary: null
@hackeronereports
π― New Report #3115705: Stored XSS in File Upload Leads to Privilege Escalation and Full Workspace Takeover
πΊSeverity: High
π½ Reporter: sjalu
πΌ Team: Dust
π΅ Bounty: null
π Submitted: 2025-04-28
β° Disclosed: 2025-05-02 12:01:14
π Summary: A stored cross-site scripting (XSS) vulnerability was discovered in the Dust platform's file upload functionality. An attacker could upload a malicious HTML file to a conversation. When another user, including an admin, visited the uploaded file, JavaScript was executed in their authenticated browser session. This allowed the attacker to issue authenticated API requests on behalf of the victim, including promoting their own account to admin, downgrading or removing legitimate admins, accessing and deleting secrets, and gaining full control over the workspace.
@hackeronereports
πΊSeverity: High
π½ Reporter: sjalu
πΌ Team: Dust
π΅ Bounty: null
π Submitted: 2025-04-28
β° Disclosed: 2025-05-02 12:01:14
π Summary: A stored cross-site scripting (XSS) vulnerability was discovered in the Dust platform's file upload functionality. An attacker could upload a malicious HTML file to a conversation. When another user, including an admin, visited the uploaded file, JavaScript was executed in their authenticated browser session. This allowed the attacker to issue authenticated API requests on behalf of the victim, including promoting their own account to admin, downgrading or removing legitimate admins, accessing and deleting secrets, and gaining full control over the workspace.
@hackeronereports
π― New Report #3088290: Middleware Authentication Bypass on IBM Portal
πΊSeverity: Critical
π½ Reporter: muhammadwaseem3
πΌ Team: IBM
π΅ Bounty: null
π Submitted: 2025-04-11
β° Disclosed: 2025-05-02 14:58:27
π Summary: The vulnerability of middleware authentication bypass on the IBM Portal endpoint was reported, analyzed, and remediated. The discovery was reported by an external researcher.
@hackeronereports
πΊSeverity: Critical
π½ Reporter: muhammadwaseem3
πΌ Team: IBM
π΅ Bounty: null
π Submitted: 2025-04-11
β° Disclosed: 2025-05-02 14:58:27
π Summary: The vulnerability of middleware authentication bypass on the IBM Portal endpoint was reported, analyzed, and remediated. The discovery was reported by an external researcher.
@hackeronereports
π― New Report #2265413: Open Redirect on https://api.fastly.com/
πΊSeverity: Low
π½ Reporter: hasn0x
πΌ Team: Fastly VDP
π΅ Bounty: null
π Submitted: 2023-11-27
β° Disclosed: 2025-05-02 19:10:10
π Summary: The open redirect vulnerability on https://api.fastly.com/ was discovered. The vulnerability allowed user redirection to a malicious website by modifying the "redirect url" parameter. The issue was identified through the steps provided in the report.
@hackeronereports
πΊSeverity: Low
π½ Reporter: hasn0x
πΌ Team: Fastly VDP
π΅ Bounty: null
π Submitted: 2023-11-27
β° Disclosed: 2025-05-02 19:10:10
π Summary: The open redirect vulnerability on https://api.fastly.com/ was discovered. The vulnerability allowed user redirection to a malicious website by modifying the "redirect url" parameter. The issue was identified through the steps provided in the report.
@hackeronereports
π― New Report #3097900: `/names.nsf` and all `/names*` files route to public API on rubygems.org
πΊSeverity: None
π½ Reporter: jagat-singh
πΌ Team: RubyGems
π΅ Bounty: null
π Submitted: 2025-04-16
β° Disclosed: 2025-05-03 16:00:09
π Summary: null
@hackeronereports
πΊSeverity: None
π½ Reporter: jagat-singh
πΌ Team: RubyGems
π΅ Bounty: null
π Submitted: 2025-04-16
β° Disclosed: 2025-05-03 16:00:09
π Summary: null
@hackeronereports
π― New Report #3125832: HTTP/3 Stream Dependency Cycle Exploit
πΊSeverity: High
π½ Reporter: evilginx
πΌ Team: curl
π΅ Bounty: null
π Submitted: 2025-05-04
β° Disclosed: 2025-05-04 15:52:29
π Summary: null
@hackeronereports
πΊSeverity: High
π½ Reporter: evilginx
πΌ Team: curl
π΅ Bounty: null
π Submitted: 2025-05-04
β° Disclosed: 2025-05-04 15:52:29
π Summary: null
@hackeronereports
π― New Report #3112106: BAC β Bypass chatbot restrictions via unauthorized mention injection
πΊSeverity: Medium
π½ Reporter: yoyomiski
πΌ Team: Dust
π΅ Bounty: null
π Submitted: 2025-04-25
β° Disclosed: 2025-05-06 14:24:05
π Summary: The Gemini chatbot was found to have a vulnerability that allowed unauthorized users to bypass permission restrictions and interact with the chatbot. The vulnerability was discovered when a user manually edited the request by changing the "mention" and "configurationId" fields, which allowed them to communicate with the disabled Gemini chatbot despite not having the proper permissions.
@hackeronereports
πΊSeverity: Medium
π½ Reporter: yoyomiski
πΌ Team: Dust
π΅ Bounty: null
π Submitted: 2025-04-25
β° Disclosed: 2025-05-06 14:24:05
π Summary: The Gemini chatbot was found to have a vulnerability that allowed unauthorized users to bypass permission restrictions and interact with the chatbot. The vulnerability was discovered when a user manually edited the request by changing the "mention" and "configurationId" fields, which allowed them to communicate with the disabled Gemini chatbot despite not having the proper permissions.
@hackeronereports
π― New Report #3079966: HTML Injection in LinkedIn Premium Support Chat
πΊSeverity: Low
π½ Reporter: nagu123
πΌ Team: LinkedIn
π΅ Bounty: null
π Submitted: 2025-04-06
β° Disclosed: 2025-05-07 07:53:59
π Summary: The vulnerability exists in the LinkedIn Premium support chat interface where unsanitized HTML input was rendered directly in the chat window. An attacker could have exploited this by injecting malicious HTML such as clickable links, potentially leading to phishing or redirection attacks on LinkedIn support staff. The observed behavior was that HTML, such as
@hackeronereports
πΊSeverity: Low
π½ Reporter: nagu123
πΌ Team: LinkedIn
π΅ Bounty: null
π Submitted: 2025-04-06
β° Disclosed: 2025-05-07 07:53:59
π Summary: The vulnerability exists in the LinkedIn Premium support chat interface where unsanitized HTML input was rendered directly in the chat window. An attacker could have exploited this by injecting malicious HTML such as clickable links, potentially leading to phishing or redirection attacks on LinkedIn support staff. The observed behavior was that HTML, such as
<a> tags, was rendered in the chat and appeared clickable to support agents. The expected behavior was that user input in chat should have been sanitized and rendered as plain text without interpreting any HTML or tags.@hackeronereports