Hackerone Reports
222 subscribers
726 links
Last Check 2026-09-16 00:45:01
Download Telegram
🎯 New Report #3150884: CVE-2025-4947: QUIC certificate check skip with wolfSSL
🔺Severity: Medium
👽 Reporter: kurohiro
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-17
Disclosed: 2025-05-28 06:35:36
📝 Summary: null
@hackeronereports
🎯 New Report #2800091: Non-Production API Endpoints for the bedrock-agent Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration
🔺Severity: Medium
👽 Reporter: nick frichette dd
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2024-10-23
Disclosed: 2025-05-28 00:39:38
📝 Summary: The non-production API endpoints for the bedrock-agent service failed to log to CloudTrail, resulting in silent permission enumeration. A total of 26 non-production endpoints were found that could be used with standard IAM credentials without generating CloudTrail logs. This vulnerability was considered a security issue by AWS, as it allowed for invisible enumeration of permissions.
@hackeronereports
🎯 New Report #3073507: Apache Airflow Fab Provider: Application does not invalidate session after password change via Airflow cli
🔺Severity: Low
👽 Reporter: saurabhb
💼 Team: Internet Bug Bounty
💵 Bounty: null
🕐 Submitted: 2025-04-02
Disclosed: 2025-05-29 12:43:25
📝 Summary: The Apache Airflow Fab Provider before version 1.5.2 was affected by an insufficient session expiration vulnerability. When a user's password was changed using the admin CLI, the existing user sessions were not cleared, allowing logged-in users to continue accessing the system even after the password change. This issue was addressed in version 1.5.2 of the Apache Airflow Fab Provider.
@hackeronereports
🎯 New Report #3119034: Facebook Username Takeover via Broken Link in Footer
🔺Severity: Low
👽 Reporter: vulnerability is here
💼 Team: Omise
💵 Bounty: null
🕐 Submitted: 2025-04-30
Disclosed: 2025-05-30 05:22:42
📝 Summary: The Facebook username "Opnglobal" was available for takeover due to a broken link in the footer of the target URL. The vulnerability allowed an attacker to create a fake Facebook page that could mislead users and negatively impact the organization's social media presence.
@hackeronereports
🎯 New Report #1365076: Information Disclosure of metrics fax.wavecell.com/metrics
🔺Severity: Low
👽 Reporter: kauenavarro
💼 Team: 8x8 Bounty
💵 Bounty: null
🕐 Submitted: 2021-10-10
Disclosed: 2025-05-30 06:53:23
📝 Summary: The fax.wavecell.com/metrics endpoint was found to disclose sensitive information. The information disclosure vulnerability was discovered and reported on the HackerOne platform.
@hackeronereports
🎯 New Report #2937622: Public GitHub repositories for multiple HackerOne managed triage team profiles contain private HackerOne reports information
🔺Severity: Low
👽 Reporter: w2w
💼 Team: HackerOne
💵 Bounty: 1200
🕐 Submitted: 2025-01-14
Disclosed: 2025-05-31 10:11:51
📝 Summary: Publicly available GitHub repositories for HackerOne-managed triage team profiles were found to contain private HackerOne vulnerability reports. Several repositories were identified that reproduced exploits for private bug bounty programs. The disclosed information included details such as access tokens, server URLs, and secret leaks for various organizations' tools and services.
@hackeronereports
🎯 New Report #3154983: IDOR: Account Deletion via Session Misbinding – Attacker Can Delete Victim Account
🔺Severity: High
👽 Reporter: z3phyrus
💼 Team: Mozilla
💵 Bounty: 6000
🕐 Submitted: 2025-05-20
Disclosed: 2025-06-03 08:38:03
📝 Summary: A critical vulnerability was identified in the Firefox Accounts API that allowed an authenticated attacker to permanently delete any user's account by sending a POST /v1/account/destroy request using the attacker's session, but including the victim's email and password hash in the JSON payload. The server failed to verify that the session making the request belonged to the account being deleted.
@hackeronereports
🎯 New Report #3165242: Server-Side Request Forgery (SSRF) via Game Export API
🔺Severity: Critical
👽 Reporter: oblivionsage
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-05-28
Disclosed: 2025-06-03 12:56:00
📝 Summary: The Lichess game export API was found to be vulnerable to Server-Side Request Forgery (SSRF) due to insufficient input validation of the "players" parameter. This allowed an attacker to make the Lichess server send arbitrary HTTP requests to external URLs, potentially exposing sensitive information.
@hackeronereports
🎯 New Report #3168039: CVE-2025-5399: WebSocket endless loop
🔺Severity: Low
👽 Reporter: z2
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-30
Disclosed: 2025-06-04 05:57:17
📝 Summary: The function curl ws send() in libcurl contains an infinite loop that can be triggered by a malicious server under specific circumstances. The loop is caused by a condition in the code that is not properly handled, leading to the function failing to terminate. This vulnerability was discovered in the libcurl library on commit 12d13b84fa40aa657b83d5458944dbd9b978fb7e.
@hackeronereports
🎯 New Report #1544236: returnUrl= allow attacker to redirect users to the another phising website and takeover credientials
🔺Severity: Medium
👽 Reporter: basant0x01
💼 Team: Insightly
💵 Bounty: null
🕐 Submitted: 2022-04-19
Disclosed: 2025-06-04 13:12:48
📝 Summary: The application at https://crm.na1.insightly.com was found to be vulnerable to a redirection attack. An attacker could manipulate the "returnUrl" parameter in the login authentication process to redirect users to a malicious website, potentially enabling the takeover of victims' accounts.
@hackeronereports
🎯 New Report #1695604: DoS Vulnerability via Cache Poisoning on cdn.shopify.com and shopify-assets.shopifycdn.com
🔺Severity: Medium
👽 Reporter: bassem sadaqah
💼 Team: Shopify
💵 Bounty: 3800
🕐 Submitted: 2022-09-08
Disclosed: 2025-06-04 19:07:38
📝 Summary: There was a web cache poisoning vulnerability on Shopify's CDN domains that allowed an attacker to block access to any file hosted on the website. The vulnerability existed because the cache server treated backslashes and forward slashes as equivalent, while the origin server returned 404 errors for paths with backslashes. This discrepancy was exploited to cache 404 error pages for legitimate requests, causing a Denial of Service condition.
@hackeronereports
🎯 New Report #3081691: 1 Click Account Takeover via Auth Token Theft on marketing.hostinger.com
🔺Severity: High
👽 Reporter: aziz0x48
💼 Team: hostinger
💵 Bounty: null
🕐 Submitted: 2025-04-07
Disclosed: 2025-06-06 12:10:25
📝 Summary: The vulnerability discovered in the marketing.hostinger.com subdomain allowed for one-click account takeover through the theft of authentication tokens. An attacker could exploit the whitelisted redirect functionality of the subdomain to steal a victim's authentication token, which could then be used to gain full access to the victim's Hostinger account.
@hackeronereports
2
🎯 New Report #3175928: ImageId Format Injection in Image Upload Endpoint
🔺Severity: Medium
👽 Reporter: oblivionsage
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-03
Disclosed: 2025-06-06 17:43:33
📝 Summary: The image upload endpoint in the Lichess application did not properly validate the 'rel' parameter, allowing an attacker to inject special characters that broke the expected format of the generated ImageId. This could have led to parsing issues in other parts of the application that relied on the standard ImageId format.
@hackeronereports
🎯 New Report #2633771: IDOR Vulnerability at AddTagToAssets operation name
🔺Severity: Medium
👽 Reporter: root geek280
💼 Team: HackerOne
💵 Bounty: null
🕐 Submitted: 2024-07-31
Disclosed: 2025-06-08 16:28:23
📝 Summary: The IDOR vulnerability was discovered in the AddTagToAssets operation name of a GraphQL endpoint. The vulnerability allowed an attacker to obtain the IDs of custom tags created by a victim by decoding the base64-encoded tagId parameter in the request. This revealed the format and pattern of the tag IDs, enabling the attacker to perform a brute-force attack to disclose the victim's custom tags without any interaction with the victim.
@hackeronereports
🎯 New Report #3181066: Path Traversal Vulnerability in Lila Project
🔺Severity: High
👽 Reporter: immm
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-06
Disclosed: 2025-06-09 11:30:57
📝 Summary: A path traversal vulnerability was discovered in the Lila project that allowed an attacker to access arbitrary files on the server by manipulating user-supplied input to traverse outside the intended directory structure.
@hackeronereports
🎯 New Report #2894018: Lack of Feedback Validation Permits Arbitrary Driver Ratings
🔺Severity: Medium
👽 Reporter: bugbountywithmarco
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-12-10
Disclosed: 2025-06-12 13:26:15
📝 Summary: The vulnerability discovered by @bugbountywithmarco in Bykea's feedback system allowed authenticated passengers to submit feedback for drivers they had not actually ridden with. The exploit was limited to trips the attacker legitimately owned, and each trip could only affect one driver rating at a time. However, this flaw could still be abused to unfairly manipulate driver scores, undermining the reliability of the platform's reputation system.
@hackeronereports
🎯 New Report #2489843: Crafted smart contract can take 1.5 minutes to execute due to inefficient CODESIZE implementation
🔺Severity: Medium
👽 Reporter: guido
💼 Team: Rootstock Labs
💵 Bounty: null
🕐 Submitted: 2024-05-03
Disclosed: 2025-06-12 18:52:48
📝 Summary: The crafted smart contract can take 1.5 minutes to execute due to an inefficient implementation of the CODESIZE operation in the VM. The issue was caused by the VM.doCODESIZE() method, which retrieved the entire code array instead of just the code length. This behavior could be exploited to transfer large amounts of data, leading to a significant slowdown in contract execution.
@hackeronereports
🔥1
🎯 New Report #2559404: Crafted smart contract can take ~23 seconds to execute due to immense error string construction
🔺Severity: Medium
👽 Reporter: guido
💼 Team: Rootstock Labs
💵 Bounty: null
🕐 Submitted: 2024-06-18
Disclosed: 2025-06-12 18:52:17
📝 Summary: The crafted smart contract can take approximately 23 seconds to execute due to the immense error string construction. The vulnerability was caused by the native contract's implementation, which constructed the entirety of the input message as a hex string for logging and throwing an exception. This approach resulted in a significantly longer execution time when provided with a large, invalid input.
@hackeronereports
🔥1
🎯 New Report #3146996: [XSS Reflected XSS via POST request in (███████)](https://hackerone.com/reports/3146996)
🔺Severity: Medium
👽 Reporter: morphykutay
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-05-14
Disclosed: 2025-06-12 20:24:38
📝 Summary: A reflected Cross-Site Scripting (XSS) vulnerability was identified in the celular parameter of a POST request to the homepage of a Mars-owned website. The vulnerability was classified as medium severity with a CVSS score of 6.2. The application failed to properly sanitize user input before rendering it in the response, which allowed arbitrary JavaScript code to be executed in the victim's browser context. The vulnerability was initially reported on May 14, 2025 and was subsequently verified by the security team. After remediation efforts, the issue was confirmed as resolved on June 11, 2025. The vulnerability fell under CWE-79 (Improper Neutralization of Input During Web Page Generation).
@hackeronereports
🎯 New Report #2861888: Ability to increase any customer offered fare (BAC)
🔺Severity: Medium
👽 Reporter: grassye
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-11-23
Disclosed: 2025-06-13 04:52:25
📝 Summary: A business logic flaw was discovered that allowed a malicious passenger or driver (acting as a passenger) to increase the fare of another customer's ride without their involvement. By chaining two unauthenticated endpoints, an attacker could cause an inflated fare to appear on the driver's screen.
@hackeronereports
🎯 New Report #2374730: Broken Access Control (IDOR) in Booking Detail and Bids Could Leads to Sensitive Information Disclosure
🔺Severity: High
👽 Reporter: back2arie
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-02-15
Disclosed: 2025-06-13 04:36:06
📝 Summary: The report identified a vulnerability in the Bykea application's booking detail and bids endpoints that could lead to the disclosure of sensitive information. The vulnerable endpoints allowed an attacker to access the booking details, bids information, and bids configuration of other users by modifying the booking id parameter in the request URL. This issue was classified as an Insecure Direct Object Reference (IDOR) vulnerability.
@hackeronereports