Hackerone Reports
226 subscribers
743 links
Last Check 2026-09-19 00:45:01
Download Telegram
🎯 New Report #2915426: Git repository found
🔺Severity: High
👽 Reporter: tefa
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-12-27
Disclosed: 2025-07-07 10:16:58
📝 Summary: null
📂 Report JSON File: 2915426
@hackeronereports
🎯 New Report #3238249: Integer Overflow Risk in HTTP/2 Proxy Window Size Calculations
🔺Severity: Medium
👽 Reporter: extramayoextracheeseextrafries
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-06
Disclosed: 2025-07-07 10:16:48
📝 Summary: null
📂 Report JSON File: 3238249
@hackeronereports
🎯 New Report #2402842: Information disclosure identified on IBM endpoint.
🔺Severity: Medium
👽 Reporter: devire
🛠 State: resolved
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2024-03-05
Disclosed: 2025-07-08 14:50:58
📝 Summary: The information disclosure vulnerability identified on an IBM endpoint was reported to IBM, analyzed, and remediated.
📂 Report JSON File: 2402842
@hackeronereports
🎯 New Report #3230359: CSRF at Network feature
🔺Severity: Medium
👽 Reporter: psfauzi
🛠 State: resolved
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-30
Disclosed: 2025-07-08 14:19:58
📝 Summary: A CSRF vulnerability was found in the network feature, where an attacker could change the Network Routing settings by sending a CSRF script to the victim.
📂 Report JSON File: 3230359
@hackeronereports
🎯 New Report #3241304: access notes without permission
🔺Severity: None
👽 Reporter: haydradz
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-08
Disclosed: 2025-07-08 19:54:37
📝 Summary: null
📂 Report JSON File: 3241304
@hackeronereports
🎯 New Report #3241308: Disclosure of email addresses
🔺Severity: None
👽 Reporter: haydradz
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-08
Disclosed: 2025-07-08 19:53:51
📝 Summary: null
📂 Report JSON File: 3241308
@hackeronereports
🎯 New Report #1485717: ReDoS in IPAddr
🔺Severity: null
👽 Reporter: ooooooo q
🛠 State: resolved
💼 Team: Ruby
💵 Bounty: null
🕐 Submitted: 2022-02-19
Disclosed: 2025-07-08 22:57:09
📝 Summary: The Ruby IPAddr library was found to be vulnerable to a ReDoS (Regular Expression Denial of Service) vulnerability. The vulnerability was identified in the mask! method, which used a regular expression that was susceptible to exponential backtracking when processing malformed input. This could have led to a denial of service condition when the library was used to process user-supplied IP addresses.
📂 Report JSON File: 1485717
@hackeronereports
🎯 New Report #1487889: ReDoS in Psych
🔺Severity: null
👽 Reporter: ooooooo q
🛠 State: resolved
💼 Team: Ruby
💵 Bounty: null
🕐 Submitted: 2022-02-21
Disclosed: 2025-07-08 22:56:51
📝 Summary: The Psych library in Ruby was found to have a ReDoS (Regular Expression Denial of Service) vulnerability in the parsing of time strings. The vulnerability was identified in the regular expression used to extract date and time information from the input string. The regular expression was susceptible to catastrophic backtracking, which could lead to significant performance degradation when parsing malformed input.
📂 Report JSON File: 1487889
@hackeronereports
🎯 New Report #3242087: Arbitrary File Read via file:// Protocol in cURL
🔺Severity: Critical
👽 Reporter: mr tufan
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-09
Disclosed: 2025-07-09 07:23:25
📝 Summary: null
📂 Report JSON File: 3242087
@hackeronereports
⚠️ The new version of the HackerOne report monitoring bot has been updated:

1️⃣. Initial reports are now stored as JSON files on GitHub.
2️⃣. From now on, "not-applicable" reports will not be displayed in the channel.
3️⃣. The report status, which can be closed as "resolved" or "informative," will be shown.
🔥Good luck crushing it in your bug hunts!

@hackeronereports
🎯 New Report #3099978: Leaked reused password for a few Khan Academy users
🔺Severity: High
👽 Reporter: a0xtrojan
🛠 State: resolved
💼 Team: Khan Academy
💵 Bounty: null
🕐 Submitted: 2025-04-18
Disclosed: 2025-07-12 10:31:05
📝 Summary: Leaked reused passwords for a few Khan Academy users were discovered on a Telegram bot. The exact source of the leaked data is unknown, but the volume of exposed information is substantial, including user emails and passwords.
📂 Report JSON File: 3099978
@hackeronereports
😱1
🎯 New Report #3181802: Reflected XSS in "Client Notes" Field
🔺Severity: Low
👽 Reporter: rishail01
🛠 State: resolved
💼 Team: MainWP
💵 Bounty: 50
🕐 Submitted: 2025-06-06
Disclosed: 2025-07-13 16:47:10
📝 Summary: A reflected Cross-Site Scripting (XSS) vulnerability was discovered in the "Notes" functionality under the Edit Client section. User input in the notes input field was not properly sanitized or encoded, allowing malicious JavaScript payloads to be reflected back in the application's HTML response upon submission. While this vulnerability was not directly exploitable by other users, it highlighted a potential entry point for more severe XSS vulnerabilities in the application.
📂 Report JSON File: 3181802
@hackeronereports
🎯 New Report #3131758: HashDoS in V8
🔺Severity: High
👽 Reporter: sharp edged
⭐️ Reputation: 107
🛠 State: resolved
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2025-05-06
Disclosed: 2025-07-15 22:49:53
📝 Summary: The V8 release used in Node.js v24.0.0 changed how string hashes were computed using rapidhash. This implementation reintroduced the HashDoS vulnerability, where an attacker who could control the strings to be hashed could generate many hash collisions without knowing the hash-seed.
📂 Report JSON File: 3131758
@hackeronereports
🎯 New Report #3160912: Windows Device Names (CON, PRN, AUX) Bypass Path Traversal Protection in path.normalize()
🔺Severity: High
👽 Reporter: oblivionsage
⭐️ Reputation: 246
🛠 State: resolved
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2025-05-23
Disclosed: 2025-07-15 22:44:08
📝 Summary: An incomplete fix has been identified for a vulnerability affecting Windows device names in the path.normalize() function in Node.js. The vulnerability allows path traversal protection to be bypassed on devices such as CON, PRN, and AUX.
📂 Report JSON File: 3160912
@hackeronereports
🔥1
🎯 New Report #1577940: Banned user still has access to their deleted account via HackerOne's API using their API key
🔺Severity: Medium
👽 Reporter: mrmax4o4
⭐️ Reputation: 3165
🛠 State: resolved
💼 Team: HackerOne
💵 Bounty: null
🕐 Submitted: 2022-05-22
Disclosed: 2025-07-14 20:50:35
📝 Summary: The user's banned account could still be accessed using their previously generated API token, allowing them to perform actions such as retrieving reports, balance, earnings, payouts, weaknesses, and program information. This vulnerability was discovered and exploited on a test account.
📂 Report JSON File: 1577940
@hackeronereports
🎯 New Report #3179850: exposure of personal IP address via email.
🔺Severity: null
👽 Reporter: micael1
⭐️ Reputation: 84
🛠 State: resolved
💼 Team: Weblate
💵 Bounty: null
🕐 Submitted: 2025-06-05
Disclosed: 2025-07-16 12:37:20
📝 Summary: The exposure of personal IP address through email was identified as a potential privacy concern. Email messages, even with TLS encryption, can pass through various servers that may store or record the content, including the user's IP address. This IP address can be considered personally identifiable information and may reveal information about the user's location, internet service provider, and device. It was recommended to avoid including raw IP addresses in outbound email messages and instead provide approximate location or prompt users to review login activity through a secure dashboard, in order to adhere to security principles such as least privilege and data minimization.
📂 Report JSON File: 3179850
@hackeronereports
🎯 New Report #3185205: Reflected XSS in "Cost Tracker" Notes Field
🔺Severity: Low
👽 Reporter: rishail01
⭐️ Reputation: 200
🛠 State: resolved
💼 Team: MainWP
💵 Bounty: 50
🕐 Submitted: 2025-06-10
Disclosed: 2025-07-17 09:08:50
📝 Summary: The reflected Cross-Site Scripting (XSS) vulnerability was discovered in the "Notes" input field of the Cost Tracker section in MainWP (Version 5.4.0.11). Arbitrary user input in this field was reflected back and executed immediately upon saving, due to the lack of proper input sanitization and output encoding.
📂 Report JSON File: 3185205
@hackeronereports
🎯 New Report #3181803: Reflected XSS in "Manage Tags" Notes Field
🔺Severity: Low
👽 Reporter: rishail01
⭐️ Reputation: 200
🛠 State: resolved
💼 Team: MainWP
💵 Bounty: 50
🕐 Submitted: 2025-06-06
Disclosed: 2025-07-17 09:07:48
📝 Summary: A reflected Cross-Site Scripting (XSS) vulnerability was discovered in the "Notes" input field under the Manage Tags section. Arbitrary input entered into this field was reflected back and executed immediately upon saving, due to the lack of proper input sanitization and output encoding.
📂 Report JSON File: 3181803
@hackeronereports
🎯 New Report #3179138: Reflected XSS in "Create Category" Functionality of Post Creation Module
🔺Severity: Low
👽 Reporter: rishail01
⭐️ Reputation: 200
🛠 State: resolved
💼 Team: MainWP
💵 Bounty: 50
🕐 Submitted: 2025-06-05
Disclosed: 2025-07-17 09:07:36
📝 Summary: A reflected Cross-Site Scripting (XSS) vulnerability was identified in the "Create Category" feature of the post creation functionality. When a user entered a malicious JavaScript payload in the Category Name field, the input was reflected and executed immediately after submission. However, this XSS only executed in the attacker's own session and did not persist or affect other users.
📂 Report JSON File: 3179138
@hackeronereports
🎯 New Report #3176981: Stored Cross-Site Scripting (XSS) in "Add Contact" Name Field – MainWP Plugin
🔺Severity: null
👽 Reporter: rishail01
⭐️ Reputation: 200
🛠 State: resolved
💼 Team: MainWP
💵 Bounty: 50
🕐 Submitted: 2025-06-04
Disclosed: 2025-07-17 09:07:14
📝 Summary: A stored cross-site scripting (XSS) vulnerability was discovered in the MainWP WordPress plugin. The vulnerability was found in the "Add Contact" > Contact Name field, where user input was not properly sanitized before rendering it back into the DOM. As a result, an attacker could inject malicious JavaScript payloads that would be executed in the browser of any user, typically an administrator, who viewed the infected client profile.
📂 Report JSON File: 3176981
@hackeronereports
🎯 New Report #3178999: Account takeover of existing HackerOne accounts through SCIM provisioning
🔺Severity: High
👽 Reporter: boy child
⭐️ Reputation: 727
🛠 State: resolved
💼 Team: HackerOne
💵 Bounty: null
🕐 Submitted: 2025-06-05
Disclosed: 2025-07-17 14:12:57
📝 Summary: The SCIM provisioning feature in HackerOne's sandbox program was vulnerable to account takeover. An attacker could create a user with an email they controlled, import existing users, assign the victim account to the attacker's user, change the email parameter, and reset the password to gain access to the victim's account. The vulnerability existed due to issues with how the username and email fields were handled during the SCIM provisioning process.
📂 Report JSON File: 3178999
@hackeronereports
🔥1