Hackerone Reports
222 subscribers
726 links
Last Check 2026-09-15 14:45:01
Download Telegram
🎯 New Report #3137657: Memory Leak
🔺Severity: null
👽 Reporter: antypanty
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-09
Disclosed: 2025-05-10 21:16:26
📝 Summary: null
@hackeronereports
🎯 New Report #2828693: change part of personal information all users
🔺Severity: Critical
👽 Reporter: bughunter0x7
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2024-11-08
Disclosed: 2025-05-12 15:13:38
📝 Summary: The report describes a vulnerability in the ██████████ website, where unauthorized access to an API endpoint allowed attackers to add new users and modify personal information of existing users. The vulnerability was classified as Improper Access Control. The issue stemmed from the absence of proper authentication and authorization mechanisms on the ██████████ endpoint, which handled user registration and profile updates. This vulnerability allowed anyone to create new user accounts or modify existing user information without requiring any authentication. Additionally, the vulnerability was compounded by a predictable user identifier system (4-digit codes) that could be easily enumerated through brute force methods to identify valid user profiles through the ██████████ endpoint.
@hackeronereports
🎯 New Report #3090123: insecure deserilize object leads to RCE On Sitecore (CVE-██████████-27218)
🔺Severity: Critical
👽 Reporter: reinhardtthe
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-04-12
Disclosed: 2025-05-12 16:04:46
📝 Summary: This critical vulnerability involved an insecure deserialization issue in Sitecore implementation, which was assigned CVE-2025-27218. The vulnerability allowed remote code execution through unsanitized user input in the ThumbnailsAccessToken header. The vulnerability was remediated by removing public access to the affected site, which was then protected behind Cloudflare WAF.
@hackeronereports
🎯 New Report #2828608: Users Data Exposure via Insecure Endpoint
🔺Severity: Medium
👽 Reporter: bughunter0x7
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2024-11-08
Disclosed: 2025-05-12 15:52:22
📝 Summary: An insecure endpoint on the Mars Royal Canin website exposed sensitive customer information without proper authentication. Personal data, including full names, phone numbers, email addresses, physical addresses, and postal codes, was accessible through a simple API endpoint that could be accessed by anyone. The endpoint revealed customer data when provided with a numeric code parameter, and all user information could potentially have been accessed by brute-forcing this parameter.
@hackeronereports
🎯 New Report #3063026: debug.log leaked [█████████](https://hackerone.com/reports/3063026)
🔺Severity: Low
👽 Reporter: imeng
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-03-27
Disclosed: 2025-05-12 15:45:47
📝 Summary: The report identified a security vulnerability in the visitor management system that exposed a debug log file containing personally identifiable information. The log file was publicly accessible without authentication, allowing unauthorized access to sensitive user data. The vulnerability was classified as an instance of insecure storage of sensitive information. The issue was subsequently resolved when the website was closed at the end of 2024.
@hackeronereports
🎯 New Report #2887506: massive PII leakage for ███████
🔺Severity: Medium
👽 Reporter: thpless
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2024-12-08
Disclosed: 2025-05-12 15:44:05
📝 Summary: The report identified a security vulnerability in the visitor management system (mwcvisitor.royalcanin.com.cn) that exposed a log file containing personally identifiable information (PII) of users. The log file was directly accessible through a public URL without any authentication, allowing unauthorized access to sensitive personal data. The vulnerability was confirmed and subsequently resolved by the Mars team, as the site was closed at the end of 2024 and the endpoint is no longer accessible.
@hackeronereports
🎯 New Report #2915647: Netlify Authentication Token Exposed in Public Mozilla CI Logs
🔺Severity: Critical
👽 Reporter: samirsec0x01
💼 Team: Mozilla
💵 Bounty: 1500
🕐 Submitted: 2024-12-27
Disclosed: 2025-05-13 09:35:01
📝 Summary: A critical vulnerability was discovered involving the exposure of a Netlify authentication token within publicly accessible logs. The token provided full access to the "Mozilla IT Web SRE" Netlify account, bypassing all restrictions. The token's permissions encompassed roles such as Owner, Developer, Billing Admin, Reviewer, Publisher, and Content Editor, granting complete control over site management, deployments, billing, and content configurations.
@hackeronereports
🎯 New Report #3098717: user api key leaked
🔺Severity: None
👽 Reporter: atasec
💼 Team: WakaTime
💵 Bounty: null
🕐 Submitted: 2025-04-17
Disclosed: 2025-05-13 14:02:20
📝 Summary: The user's API key was found exposed in an older URL while testing the WakaTime tool. The API key successfully authenticated requests to a restricted endpoint, indicating that it was valid and granted access to protected resources.
@hackeronereports
🎯 New Report #2817648: Improper error handling in async cryptographic operations crashes process
🔺Severity: High
👽 Reporter: tniessen
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2024-11-02
Disclosed: 2025-05-14 22:30:56
📝 Summary: The C method SignTraits::DeriveBits() incorrectly called ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process.
@hackeronereports
🎯 New Report #3062122: [Xenoblade Chronicles X: Definitive Edition Unrestricted RPCs allow DoS and writing arbitrary flags remotely](https://hackerone.com/reports/3062122)
🔺Severity: Critical
👽 Reporter: roccodev
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2025-03-31
Disclosed: 2025-05-15 00:11:16
📝 Summary: The Xenoblade Chronicles X: Definitive Edition vulnerability allowed attackers to perform Denial-of-Service (DoS) attacks and write arbitrary flags remotely due to unrestricted Remote Procedure Calls (RPCs).
@hackeronereports
🎯 New Report #3052880: [Xenoblade Chronicles X: Definitive Edition Improper validation of names allows injecting formatting tags and bypassing profanity filter](https://hackerone.com/reports/3052880)
🔺Severity: Medium
👽 Reporter: roccodev
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2025-03-23
Disclosed: 2025-05-15 00:11:06
📝 Summary: The vulnerability in Xenoblade Chronicles X: Definitive Edition allowed improper validation of names, enabling the injection of formatting tags and bypassing the profanity filter.
@hackeronereports
🎯 New Report #3085889: Weak Rate Limiting Controls in the (LOGIN) page Expose System to Brute Force and DoS Attacks
🔺Severity: Critical
👽 Reporter: hajjaj-
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-04-09
Disclosed: 2025-05-15 11:11:04
📝 Summary: null
@hackeronereports
🎯 New Report #3099816: Open Redirect Vulnerability in OAuth Flow Leading to Potential Phishing Attack
🔺Severity: Low
👽 Reporter: delsec
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-04-18
Disclosed: 2025-05-15 11:10:40
📝 Summary: null
@hackeronereports
🎯 New Report #3056937: Bedrock Guardrails Evasion with Prompt Formatting
🔺Severity: None
👽 Reporter: nkirk-nrlabs
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-03-25
Disclosed: 2025-05-15 16:12:27
📝 Summary: null
@hackeronereports
🎯 New Report #2885269: Shopify Partners Invitation Process Allows Privilege Escalation Without Email Verification
🔺Severity: Medium
👽 Reporter: mr asg
💼 Team: Shopify
💵 Bounty: 3500
🕐 Submitted: 2024-12-06
Disclosed: 2025-05-15 18:25:56
📝 Summary: The Shopify Partners invitation process allowed privilege escalation without email verification. The vulnerability permitted unauthorized users to gain access to Shopify Partners accounts and escalate their privileges by creating accounts using the email addresses of invited owners and accepting the invitations.
@hackeronereports
🎯 New Report #2802817: Any WARP User Can Access Organization-Specific Application
🔺Severity: None
👽 Reporter: jai-kandepu
💼 Team: Cloudflare Public Bug Bounty
💵 Bounty: null
🕐 Submitted: 2024-10-25
Disclosed: 2025-05-19 21:58:31
📝 Summary: null
@hackeronereports
🎯 New Report #3148937: `Curl socketpair()` fallback vulnerable to man-in-the-middle attack
🔺Severity: null
👽 Reporter: jmanojlovich
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-15
Disclosed: 2025-05-20 06:51:27
📝 Summary: null
@hackeronereports
🎯 New Report #3158093: Memory Leak in libcurl via Location Header Handling (CWE-770)
🔺Severity: High
👽 Reporter: darkroomdragon
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-22
Disclosed: 2025-05-22 07:19:09
📝 Summary: null
@hackeronereports
🎯 New Report #1981441: Dynamic fee algorithm doesn't check for zero fee
🔺Severity: Low
👽 Reporter: sech1
💼 Team: Monero
💵 Bounty: null
🕐 Submitted: 2023-05-10
Disclosed: 2025-05-23 14:25:46
📝 Summary: The dynamic fee algorithm in the Monero blockchain did not properly check for a zero fee, which could have allowed an attacker to flood the network with transactions at no cost, potentially leading to unlimited blockchain growth.
@hackeronereports
🎯 New Report #2338094: RPC service DOS
🔺Severity: Medium
👽 Reporter: ptrstr
💼 Team: Monero
💵 Bounty: null
🕐 Submitted: 2024-01-28
Disclosed: 2025-05-23 14:25:17
📝 Summary: The RPC service running on port 18081 (or 28081, 38081) was vulnerable to a denial-of-service attack due to a loop iterating until the maximum range of a 64-bit unsigned integer. The vulnerability was present in all versions after the commit b030f207517f59a5122409398549a02ac23829ae, up to and including version 0.18.3.1.
@hackeronereports
🎯 New Report #2084280: WASI sandbox escape via symlink
🔺Severity: Medium
👽 Reporter: jessewilson
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2023-07-25
Disclosed: 2025-05-24 10:33:57
📝 Summary: A WASI WASM program was discovered to be able to use path symlink to read arbitrary files on the host machine by creating a symlink in a preopen to a different location on the local file system, thereby escaping the WASI sandbox.
@hackeronereports