Hackerone Reports
228 subscribers
744 links
Last Check 2026-09-22 01:45:01
Download Telegram
🎯 New Report #3183957: Arbitrary File Read via Unsanitized curl Usage Results in Sensitive File Exposure
🔺Severity: None
👽 Reporter: ednaq
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-06-09
Disclosed: 2025-06-27 09:47:49
📝 Summary: null
@hackeronereports
🎯 New Report #2819573: Mutation Based Stored XSS on Trix Editor version latest (2.1.8)
🔺Severity: Critical
👽 Reporter: sudi
💼 Team: Basecamp
💵 Bounty: 6000
🕐 Submitted: 2024-11-04
Disclosed: 2025-06-27 12:55:01
📝 Summary: A vulnerability was discovered in the Trix Editor version 2.1.8 where a mutation-based stored cross-site scripting (XSS) attack was possible. The vulnerability could be exploited by crafting a malicious payload that, when copied and pasted into the editor, would trigger the execution of arbitrary JavaScript code.
@hackeronereports
🎯 New Report #2921830: Unauthorized Access to Private Video Description via Translation API for Private Accounts
🔺Severity: Low
👽 Reporter: z3phyrus
💼 Team: TikTok
💵 Bounty: null
🕐 Submitted: 2025-01-04
Disclosed: 2025-06-27 20:24:33
📝 Summary: A vulnerability was discovered in the TikTok translation API endpoint that could have allowed unauthorized access to video descriptions contained in private accounts.
@hackeronereports
🔥1
🎯 New Report #3153971: Stack Buffer Overflow in curl's OpenSSL Provider Handling
🔺Severity: Medium
👽 Reporter: oblivionsage
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-20
Disclosed: 2025-06-28 12:40:36
📝 Summary: null
@hackeronereports
🎯 New Report #3225565: OS Command Injection in scripts/firefox-db2pem.sh via untrusted certificate nicknames
🔺Severity: High
👽 Reporter: behindtheblackwall
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-06-26
Disclosed: 2025-06-28 12:19:19
📝 Summary: null
@hackeronereports
🎯 New Report #3125820: HTTP/2 CONTINUATION Flood Vulnerability
🔺Severity: High
👽 Reporter: evilginx1
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-04
Disclosed: 2025-06-28 21:13:12
📝 Summary: null
@hackeronereports
🎯 New Report #3100073: Path Traversal Vulnerability in curl via Unsanitized IPFS PATH Environment Variable
🔺Severity: High
👽 Reporter: ziad616
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-04-18
Disclosed: 2025-06-28 21:11:42
📝 Summary: null
@hackeronereports
🎯 New Report #3101127: Buffer Overflow in curl MQTT Test Server (tests/server/mqttd.c) via Malicious CONNECT Packet
🔺Severity: Critical
👽 Reporter: deep-hackerone
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-04-19
Disclosed: 2025-06-28 21:11:25
📝 Summary: null
@hackeronereports
🎯 New Report #3037326: Free of uninitialized pointer in doh decode rdata name()
🔺Severity: null
👽 Reporter: tdp3kel9g
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-03-13
Disclosed: 2025-06-28 21:10:50
📝 Summary: null
@hackeronereports
🎯 New Report #3030158: Improper Restriction of Authentication Attempts in cURL
🔺Severity: Critical
👽 Reporter: irfanmughal1122
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-03-10
Disclosed: 2025-06-28 21:09:52
📝 Summary: null
@hackeronereports
🎯 New Report #2976481: Unauthorized coins transfer from locking account(s)
🔺Severity: Critical
👽 Reporter: unknown feature
💼 Team: Cosmos
💵 Bounty: null
🕐 Submitted: 2025-02-06
Disclosed: 2025-06-29 12:30:23
📝 Summary: The Cosmos SDK was found to have a vulnerability that allowed unauthorized transfer of funds from locking accounts. The issue was specifically identified in the periodic-locking-account, but it was believed to affect other locking account types as well. The vulnerability stemmed from the way the SendCoins function validated the sender's identity, which could be bypassed when the message was packed into a MsgExecute transaction. This allowed an attacker to transfer funds from a locking account they did not own, if the account had unlocked funds after the locking period had ended.
@hackeronereports
🎯 New Report #3089595: Memory leak from doh write cb
🔺Severity: None
👽 Reporter: catenacyber
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-04-11
Disclosed: 2025-06-29 19:12:35
📝 Summary: null
@hackeronereports
🎯 New Report #3229490: Heap Buffer Overflow in libcurl curl slist append via Unterminated String
🔺Severity: High
👽 Reporter: geeknik
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-06-29
Disclosed: 2025-06-30 07:23:15
📝 Summary: null
@hackeronereports
🎯 New Report #2914705: Making transfer v2 channel unupgradable through the forwarding
🔺Severity: Low
👽 Reporter: unknown feature
💼 Team: Cosmos
💵 Bounty: null
🕐 Submitted: 2024-12-26
Disclosed: 2025-06-30 12:46:29
📝 Summary: The transfer v2 channel can become unupgradable through the forwarding functionality. The forwarding process can create packet commitments on a legitimate channel, which cannot be deleted due to the lack of acknowledgments from a malicious channel. This results in the legitimate channel being unable to transition to the "FLUSHCOMPLETE" state, preventing the channel upgrade from being completed.
@hackeronereports
🤩1
🎯 New Report #2917368: Replacing ICA active channel during the upgrade and a bit more
🔺Severity: Low
👽 Reporter: unknown feature
💼 Team: Cosmos
💵 Bounty: null
🕐 Submitted: 2024-12-30
Disclosed: 2025-06-30 12:46:22
📝 Summary: The active channel on the ICA controller was set during the channel acknowledgement, which was a check-then-act operation that was not atomic. The active channel on the ICA host was set during the channel open confirmation, but the check for the channel existence was not atomic. This allowed an attacker to create a malicious channel and set it as the active channel during an upgrade, preventing the host chain from deserializing ICA transactions until another upgrade was performed.
@hackeronereports
🎯 New Report #3136790: Unlock underage blocked app without support interaction using airplane mode
🔺Severity: Low
👽 Reporter: polem4rch
💼 Team: Tools for Humanity
💵 Bounty: 300
🕐 Submitted: 2025-05-09
Disclosed: 2025-06-30 11:20:50
📝 Summary: null
@hackeronereports
😁1
🎯 New Report #2947762: RXSS AT https://proze.yelp.com/tmsubscribe.net/vidsn.aspx
🔺Severity: Medium
👽 Reporter: 0xold
💼 Team: Yelp
💵 Bounty: null
🕐 Submitted: 2025-01-19
Disclosed: 2025-06-30 15:06:44
📝 Summary: The proze.yelp.com domain was vulnerable to Cross-Site Scripting (XSS) attacks, which allowed the injection of malicious scripts that could affect the security of users of the domain.
@hackeronereports
🎯 New Report #3120969: [High MITM via Insecure CA Path Handling in cURL (--capath, CURLOPT CAPATH) (CWE-494: Download of Code Without Integrity Check)](https://hackerone.com/reports/3120969)
🔺Severity: High
👽 Reporter: oicus
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-01
Disclosed: 2025-06-30 18:55:20
📝 Summary: null
@hackeronereports
🎯 New Report #3120987: [High Arbitrary File Write via Path Traversal in cURL CLI (-o, --output) (CWE-22: Improper Limitation of a Pathname to a Restricted Directory)](https://hackerone.com/reports/3120987)
🔺Severity: High
👽 Reporter: oicus
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-01
Disclosed: 2025-06-30 18:55:10
📝 Summary: null
@hackeronereports
🎯 New Report #3118915: Potential XSS vector in curl via unsanitized URL parameter handling
🔺Severity: High
👽 Reporter: redfoxsec
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-04-30
Disclosed: 2025-06-30 18:55:00
📝 Summary: null
@hackeronereports
🎯 New Report #3045390: Double free caused by mqtt doing()
🔺Severity: None
👽 Reporter: tdp3kel9g
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-03-18
Disclosed: 2025-06-30 18:54:49
📝 Summary: null
@hackeronereports