Hackerone Reports
222 subscribers
722 links
Last Check 2026-09-15 08:45:01
Download Telegram
🎯 New Report #2828608: Users Data Exposure via Insecure Endpoint
🔺Severity: Medium
👽 Reporter: bughunter0x7
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2024-11-08
Disclosed: 2025-05-12 15:52:22
📝 Summary: An insecure endpoint on the Mars Royal Canin website exposed sensitive customer information without proper authentication. Personal data, including full names, phone numbers, email addresses, physical addresses, and postal codes, was accessible through a simple API endpoint that could be accessed by anyone. The endpoint revealed customer data when provided with a numeric code parameter, and all user information could potentially have been accessed by brute-forcing this parameter.
@hackeronereports
🎯 New Report #3063026: debug.log leaked [█████████](https://hackerone.com/reports/3063026)
🔺Severity: Low
👽 Reporter: imeng
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-03-27
Disclosed: 2025-05-12 15:45:47
📝 Summary: The report identified a security vulnerability in the visitor management system that exposed a debug log file containing personally identifiable information. The log file was publicly accessible without authentication, allowing unauthorized access to sensitive user data. The vulnerability was classified as an instance of insecure storage of sensitive information. The issue was subsequently resolved when the website was closed at the end of 2024.
@hackeronereports
🎯 New Report #2887506: massive PII leakage for ███████
🔺Severity: Medium
👽 Reporter: thpless
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2024-12-08
Disclosed: 2025-05-12 15:44:05
📝 Summary: The report identified a security vulnerability in the visitor management system (mwcvisitor.royalcanin.com.cn) that exposed a log file containing personally identifiable information (PII) of users. The log file was directly accessible through a public URL without any authentication, allowing unauthorized access to sensitive personal data. The vulnerability was confirmed and subsequently resolved by the Mars team, as the site was closed at the end of 2024 and the endpoint is no longer accessible.
@hackeronereports
🎯 New Report #2915647: Netlify Authentication Token Exposed in Public Mozilla CI Logs
🔺Severity: Critical
👽 Reporter: samirsec0x01
💼 Team: Mozilla
💵 Bounty: 1500
🕐 Submitted: 2024-12-27
Disclosed: 2025-05-13 09:35:01
📝 Summary: A critical vulnerability was discovered involving the exposure of a Netlify authentication token within publicly accessible logs. The token provided full access to the "Mozilla IT Web SRE" Netlify account, bypassing all restrictions. The token's permissions encompassed roles such as Owner, Developer, Billing Admin, Reviewer, Publisher, and Content Editor, granting complete control over site management, deployments, billing, and content configurations.
@hackeronereports
🎯 New Report #3098717: user api key leaked
🔺Severity: None
👽 Reporter: atasec
💼 Team: WakaTime
💵 Bounty: null
🕐 Submitted: 2025-04-17
Disclosed: 2025-05-13 14:02:20
📝 Summary: The user's API key was found exposed in an older URL while testing the WakaTime tool. The API key successfully authenticated requests to a restricted endpoint, indicating that it was valid and granted access to protected resources.
@hackeronereports
🎯 New Report #2817648: Improper error handling in async cryptographic operations crashes process
🔺Severity: High
👽 Reporter: tniessen
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2024-11-02
Disclosed: 2025-05-14 22:30:56
📝 Summary: The C method SignTraits::DeriveBits() incorrectly called ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process.
@hackeronereports
🎯 New Report #3062122: [Xenoblade Chronicles X: Definitive Edition Unrestricted RPCs allow DoS and writing arbitrary flags remotely](https://hackerone.com/reports/3062122)
🔺Severity: Critical
👽 Reporter: roccodev
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2025-03-31
Disclosed: 2025-05-15 00:11:16
📝 Summary: The Xenoblade Chronicles X: Definitive Edition vulnerability allowed attackers to perform Denial-of-Service (DoS) attacks and write arbitrary flags remotely due to unrestricted Remote Procedure Calls (RPCs).
@hackeronereports
🎯 New Report #3052880: [Xenoblade Chronicles X: Definitive Edition Improper validation of names allows injecting formatting tags and bypassing profanity filter](https://hackerone.com/reports/3052880)
🔺Severity: Medium
👽 Reporter: roccodev
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2025-03-23
Disclosed: 2025-05-15 00:11:06
📝 Summary: The vulnerability in Xenoblade Chronicles X: Definitive Edition allowed improper validation of names, enabling the injection of formatting tags and bypassing the profanity filter.
@hackeronereports
🎯 New Report #3085889: Weak Rate Limiting Controls in the (LOGIN) page Expose System to Brute Force and DoS Attacks
🔺Severity: Critical
👽 Reporter: hajjaj-
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-04-09
Disclosed: 2025-05-15 11:11:04
📝 Summary: null
@hackeronereports
🎯 New Report #3099816: Open Redirect Vulnerability in OAuth Flow Leading to Potential Phishing Attack
🔺Severity: Low
👽 Reporter: delsec
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-04-18
Disclosed: 2025-05-15 11:10:40
📝 Summary: null
@hackeronereports
🎯 New Report #3056937: Bedrock Guardrails Evasion with Prompt Formatting
🔺Severity: None
👽 Reporter: nkirk-nrlabs
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-03-25
Disclosed: 2025-05-15 16:12:27
📝 Summary: null
@hackeronereports
🎯 New Report #2885269: Shopify Partners Invitation Process Allows Privilege Escalation Without Email Verification
🔺Severity: Medium
👽 Reporter: mr asg
💼 Team: Shopify
💵 Bounty: 3500
🕐 Submitted: 2024-12-06
Disclosed: 2025-05-15 18:25:56
📝 Summary: The Shopify Partners invitation process allowed privilege escalation without email verification. The vulnerability permitted unauthorized users to gain access to Shopify Partners accounts and escalate their privileges by creating accounts using the email addresses of invited owners and accepting the invitations.
@hackeronereports
🎯 New Report #2802817: Any WARP User Can Access Organization-Specific Application
🔺Severity: None
👽 Reporter: jai-kandepu
💼 Team: Cloudflare Public Bug Bounty
💵 Bounty: null
🕐 Submitted: 2024-10-25
Disclosed: 2025-05-19 21:58:31
📝 Summary: null
@hackeronereports
🎯 New Report #3148937: `Curl socketpair()` fallback vulnerable to man-in-the-middle attack
🔺Severity: null
👽 Reporter: jmanojlovich
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-15
Disclosed: 2025-05-20 06:51:27
📝 Summary: null
@hackeronereports
🎯 New Report #3158093: Memory Leak in libcurl via Location Header Handling (CWE-770)
🔺Severity: High
👽 Reporter: darkroomdragon
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-22
Disclosed: 2025-05-22 07:19:09
📝 Summary: null
@hackeronereports
🎯 New Report #1981441: Dynamic fee algorithm doesn't check for zero fee
🔺Severity: Low
👽 Reporter: sech1
💼 Team: Monero
💵 Bounty: null
🕐 Submitted: 2023-05-10
Disclosed: 2025-05-23 14:25:46
📝 Summary: The dynamic fee algorithm in the Monero blockchain did not properly check for a zero fee, which could have allowed an attacker to flood the network with transactions at no cost, potentially leading to unlimited blockchain growth.
@hackeronereports
🎯 New Report #2338094: RPC service DOS
🔺Severity: Medium
👽 Reporter: ptrstr
💼 Team: Monero
💵 Bounty: null
🕐 Submitted: 2024-01-28
Disclosed: 2025-05-23 14:25:17
📝 Summary: The RPC service running on port 18081 (or 28081, 38081) was vulnerable to a denial-of-service attack due to a loop iterating until the maximum range of a 64-bit unsigned integer. The vulnerability was present in all versions after the commit b030f207517f59a5122409398549a02ac23829ae, up to and including version 0.18.3.1.
@hackeronereports
🎯 New Report #2084280: WASI sandbox escape via symlink
🔺Severity: Medium
👽 Reporter: jessewilson
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2023-07-25
Disclosed: 2025-05-24 10:33:57
📝 Summary: A WASI WASM program was discovered to be able to use path symlink to read arbitrary files on the host machine by creating a symlink in a preopen to a different location on the local file system, thereby escaping the WASI sandbox.
@hackeronereports
🎯 New Report #2939104: CVE-2024-56374: Denial-of-service vulnerability in IPv6 validation
🔺Severity: Medium
👽 Reporter: sav
💼 Team: Internet Bug Bounty
💵 Bounty: 2162
🕐 Submitted: 2025-01-15
Disclosed: 2025-05-27 12:26:37
📝 Summary: A denial-of-service vulnerability was discovered in Django's IPv6 validation. The lack of an upper bound limit enforcement in strings passed during IPv6 validation could lead to a potential denial-of-service attack. The vulnerable functions, clean ipv6 address and is valid ipv6 address, as well as the django.forms.GenericIPAddressField form field, have been updated to address this issue.
@hackeronereports
🎯 New Report #2978267: TLS client authentication can be bypassed due to ticket resumption
🔺Severity: Medium
👽 Reporter: snhebrok
💼 Team: Internet Bug Bounty
💵 Bounty: 2162
🕐 Submitted: 2025-02-06
Disclosed: 2025-05-27 13:18:05
📝 Summary: The TLS client authentication can be bypassed due to ticket resumption. The issue was that TLS session tickets were not properly isolated for multiple virtual hosts in one server. This allowed a ticket issued for one virtual host to be resumed at a different virtual host, circumventing client authentication. The vulnerability affected both the NGINX http and NGINX stream modules.
@hackeronereports
🎯 New Report #2905013: [SECURITY CVE-2024-50379 Apache Tomcat - RCE via write-enabled default servlet](https://hackerone.com/reports/2905013)
🔺Severity: High
👽 Reporter: nacl 123
💼 Team: Internet Bug Bounty
💵 Bounty: null
🕐 Submitted: 2024-12-17
Disclosed: 2025-05-27 15:31:48
📝 Summary: A vulnerability was discovered in Apache Tomcat where a race condition could be triggered on a Windows machine with a write-enabled default servlet, leading to remote code execution. The issue was caused by the case-insensitive nature of the file system, which allowed an uploaded file to be treated as a JSP script.
@hackeronereports