Hackerone Reports
225 subscribers
743 links
Last Check 2026-09-18 22:45:01
Download Telegram
⚠️ The new version of the HackerOne report monitoring bot has been updated:

1️⃣. Initial reports are now stored as JSON files on GitHub.
2️⃣. From now on, "not-applicable" reports will not be displayed in the channel.
3️⃣. The report status, which can be closed as "resolved" or "informative," will be shown.
🔥Good luck crushing it in your bug hunts!

@hackeronereports
🎯 New Report #3099978: Leaked reused password for a few Khan Academy users
🔺Severity: High
👽 Reporter: a0xtrojan
🛠 State: resolved
💼 Team: Khan Academy
💵 Bounty: null
🕐 Submitted: 2025-04-18
Disclosed: 2025-07-12 10:31:05
📝 Summary: Leaked reused passwords for a few Khan Academy users were discovered on a Telegram bot. The exact source of the leaked data is unknown, but the volume of exposed information is substantial, including user emails and passwords.
📂 Report JSON File: 3099978
@hackeronereports
😱1
🎯 New Report #3181802: Reflected XSS in "Client Notes" Field
🔺Severity: Low
👽 Reporter: rishail01
🛠 State: resolved
💼 Team: MainWP
💵 Bounty: 50
🕐 Submitted: 2025-06-06
Disclosed: 2025-07-13 16:47:10
📝 Summary: A reflected Cross-Site Scripting (XSS) vulnerability was discovered in the "Notes" functionality under the Edit Client section. User input in the notes input field was not properly sanitized or encoded, allowing malicious JavaScript payloads to be reflected back in the application's HTML response upon submission. While this vulnerability was not directly exploitable by other users, it highlighted a potential entry point for more severe XSS vulnerabilities in the application.
📂 Report JSON File: 3181802
@hackeronereports
🎯 New Report #3131758: HashDoS in V8
🔺Severity: High
👽 Reporter: sharp edged
⭐️ Reputation: 107
🛠 State: resolved
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2025-05-06
Disclosed: 2025-07-15 22:49:53
📝 Summary: The V8 release used in Node.js v24.0.0 changed how string hashes were computed using rapidhash. This implementation reintroduced the HashDoS vulnerability, where an attacker who could control the strings to be hashed could generate many hash collisions without knowing the hash-seed.
📂 Report JSON File: 3131758
@hackeronereports
🎯 New Report #3160912: Windows Device Names (CON, PRN, AUX) Bypass Path Traversal Protection in path.normalize()
🔺Severity: High
👽 Reporter: oblivionsage
⭐️ Reputation: 246
🛠 State: resolved
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2025-05-23
Disclosed: 2025-07-15 22:44:08
📝 Summary: An incomplete fix has been identified for a vulnerability affecting Windows device names in the path.normalize() function in Node.js. The vulnerability allows path traversal protection to be bypassed on devices such as CON, PRN, and AUX.
📂 Report JSON File: 3160912
@hackeronereports
🔥1
🎯 New Report #1577940: Banned user still has access to their deleted account via HackerOne's API using their API key
🔺Severity: Medium
👽 Reporter: mrmax4o4
⭐️ Reputation: 3165
🛠 State: resolved
💼 Team: HackerOne
💵 Bounty: null
🕐 Submitted: 2022-05-22
Disclosed: 2025-07-14 20:50:35
📝 Summary: The user's banned account could still be accessed using their previously generated API token, allowing them to perform actions such as retrieving reports, balance, earnings, payouts, weaknesses, and program information. This vulnerability was discovered and exploited on a test account.
📂 Report JSON File: 1577940
@hackeronereports
🎯 New Report #3179850: exposure of personal IP address via email.
🔺Severity: null
👽 Reporter: micael1
⭐️ Reputation: 84
🛠 State: resolved
💼 Team: Weblate
💵 Bounty: null
🕐 Submitted: 2025-06-05
Disclosed: 2025-07-16 12:37:20
📝 Summary: The exposure of personal IP address through email was identified as a potential privacy concern. Email messages, even with TLS encryption, can pass through various servers that may store or record the content, including the user's IP address. This IP address can be considered personally identifiable information and may reveal information about the user's location, internet service provider, and device. It was recommended to avoid including raw IP addresses in outbound email messages and instead provide approximate location or prompt users to review login activity through a secure dashboard, in order to adhere to security principles such as least privilege and data minimization.
📂 Report JSON File: 3179850
@hackeronereports
🎯 New Report #3185205: Reflected XSS in "Cost Tracker" Notes Field
🔺Severity: Low
👽 Reporter: rishail01
⭐️ Reputation: 200
🛠 State: resolved
💼 Team: MainWP
💵 Bounty: 50
🕐 Submitted: 2025-06-10
Disclosed: 2025-07-17 09:08:50
📝 Summary: The reflected Cross-Site Scripting (XSS) vulnerability was discovered in the "Notes" input field of the Cost Tracker section in MainWP (Version 5.4.0.11). Arbitrary user input in this field was reflected back and executed immediately upon saving, due to the lack of proper input sanitization and output encoding.
📂 Report JSON File: 3185205
@hackeronereports
🎯 New Report #3181803: Reflected XSS in "Manage Tags" Notes Field
🔺Severity: Low
👽 Reporter: rishail01
⭐️ Reputation: 200
🛠 State: resolved
💼 Team: MainWP
💵 Bounty: 50
🕐 Submitted: 2025-06-06
Disclosed: 2025-07-17 09:07:48
📝 Summary: A reflected Cross-Site Scripting (XSS) vulnerability was discovered in the "Notes" input field under the Manage Tags section. Arbitrary input entered into this field was reflected back and executed immediately upon saving, due to the lack of proper input sanitization and output encoding.
📂 Report JSON File: 3181803
@hackeronereports
🎯 New Report #3179138: Reflected XSS in "Create Category" Functionality of Post Creation Module
🔺Severity: Low
👽 Reporter: rishail01
⭐️ Reputation: 200
🛠 State: resolved
💼 Team: MainWP
💵 Bounty: 50
🕐 Submitted: 2025-06-05
Disclosed: 2025-07-17 09:07:36
📝 Summary: A reflected Cross-Site Scripting (XSS) vulnerability was identified in the "Create Category" feature of the post creation functionality. When a user entered a malicious JavaScript payload in the Category Name field, the input was reflected and executed immediately after submission. However, this XSS only executed in the attacker's own session and did not persist or affect other users.
📂 Report JSON File: 3179138
@hackeronereports
🎯 New Report #3176981: Stored Cross-Site Scripting (XSS) in "Add Contact" Name Field – MainWP Plugin
🔺Severity: null
👽 Reporter: rishail01
⭐️ Reputation: 200
🛠 State: resolved
💼 Team: MainWP
💵 Bounty: 50
🕐 Submitted: 2025-06-04
Disclosed: 2025-07-17 09:07:14
📝 Summary: A stored cross-site scripting (XSS) vulnerability was discovered in the MainWP WordPress plugin. The vulnerability was found in the "Add Contact" > Contact Name field, where user input was not properly sanitized before rendering it back into the DOM. As a result, an attacker could inject malicious JavaScript payloads that would be executed in the browser of any user, typically an administrator, who viewed the infected client profile.
📂 Report JSON File: 3176981
@hackeronereports
🎯 New Report #3178999: Account takeover of existing HackerOne accounts through SCIM provisioning
🔺Severity: High
👽 Reporter: boy child
⭐️ Reputation: 727
🛠 State: resolved
💼 Team: HackerOne
💵 Bounty: null
🕐 Submitted: 2025-06-05
Disclosed: 2025-07-17 14:12:57
📝 Summary: The SCIM provisioning feature in HackerOne's sandbox program was vulnerable to account takeover. An attacker could create a user with an email they controlled, import existing users, assign the victim account to the attacker's user, change the email parameter, and reset the password to gain access to the victim's account. The vulnerability existed due to issues with how the username and email fields were handled during the SCIM provisioning process.
📂 Report JSON File: 3178999
@hackeronereports
🔥1
🎯 New Report #2831902: [CRITICAL 0-Click Account Takeover via Password Reset AUTH-3243 /orchestrator/v1/password reset/start](https://hackerone.com/reports/2831902)
🔺Severity: Critical
👽 Reporter: db3wy
⭐️ Reputation: 235
🛠 State: resolved
💼 Team: Remitly
💵 Bounty: null
🕐 Submitted: 2024-11-10
Disclosed: 2025-07-21 22:23:32
📝 Summary: The vulnerability discovered allowed an attacker to reset the password of a victim's account without any user interaction or special privileges. The attacker could intercept the password reset request, modify it with the victim's session data, and successfully take over the victim's account.
📂 Report JSON File: 2831902
@hackeronereports
🔥1
🎯 New Report #3205667: XSS on Amazon Aquisition: elemental
🔺Severity: High
👽 Reporter: muhammad kasim
⭐️ Reputation: 92
🛠 State: resolved
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-06-17
Disclosed: 2025-07-22 00:48:09
📝 Summary: The XSS vulnerability on Amazon's acquisition of Elemental was identified and addressed. The summary provided a brief overview of the issue.
📂 Report JSON File: 3205667
@hackeronereports
🎯 New Report #3258022: curl ASSERTs when accessing an LDAP URL
🔺Severity: null
👽 Reporter: cmeister2
⭐️ Reputation: 159
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-17
Disclosed: 2025-07-22 08:02:49
📝 Summary: null
📂 Report JSON File: 3258022
@hackeronereports
🎯 New Report #1148364: Mint Oauth2 access token for targeted user
🔺Severity: High
👽 Reporter: timothyleung
⭐️ Reputation: 168
🛠 State: resolved
💼 Team: GitLab
💵 Bounty: null
🕐 Submitted: 2021-04-04
Disclosed: 2025-07-23 00:06:09
📝 Summary: The vulnerability allowed a group owner to create an application that was trusted by default, bypassing CSRF controls for the authorization flow. This enabled the minting of access tokens for targeted users without their consent.
📂 Report JSON File: 1148364
@hackeronereports
🎯 New Report #3255707: Windows Device Names Still Allow Path Traversal in UNC Paths After CVE-2025-27210 Fix
🔺Severity: High
👽 Reporter: oblivionsage
⭐️ Reputation: 248
🛠 State: informative
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2025-07-16
Disclosed: 2025-07-28 18:56:39
📝 Summary: null
📂 Report JSON File: 3255707
@hackeronereports
🎯 New Report #3126603: RXSS on ██████ via customerId parameter
🔺Severity: Medium
👽 Reporter: 0xun7h1nk4ble
⭐️ Reputation: 309
🛠 State: resolved
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-05-05
Disclosed: 2025-07-28 19:17:42
📝 Summary: A Reflected Cross-Site Scripting (XSS) vulnerability was identified on the Mars website at ██████. The vulnerability was located in the customerId parameter, which was inadequately sanitized before being reflected back to users in the HTTP response. When the parameter was manipulated with malicious JavaScript code, the injected script was executed in the context of the user's browser.
📂 Report JSON File: 3126603
@hackeronereports
🎯 New Report #3261310: OpenSSL HTTP/3 bogus CURLINFO TLS SSL PTR
🔺Severity: null
👽 Reporter: nyymi
⭐️ Reputation: 1257
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-20
Disclosed: 2025-07-28 22:48:50
📝 Summary: null
📂 Report JSON File: 3261310
@hackeronereports
🎯 New Report #2995025: Mozilla VPN Clients: RCE via file write and path traversal
🔺Severity: High
👽 Reporter: trein
⭐️ Reputation: 1688
🛠 State: resolved
💼 Team: Mozilla
💵 Bounty: 6000
🕐 Submitted: 2025-02-15
Disclosed: 2025-07-29 09:53:41
📝 Summary: The report describes a path traversal vulnerability in the Mozilla VPN client software that allowed for remote code execution. The vulnerability was found in the "live reload" command of the client's inspector feature, which could be accessed when the client was in developer mode with "Use Staging Servers" enabled. The vulnerable code in the InspectorHotreloader::fetchAndAnnounce() function failed to properly sanitize file paths when downloading remote files to a temporary folder, enabling attackers to write arbitrary files to any location on the filesystem.
📂 Report JSON File: 2995025
@hackeronereports
🔥1
🎯 New Report #3175695: Bypass "No Links" Restriction in Biography via Protocol-Relative URL (//)
🔺Severity: Low
👽 Reporter: yoyomiski
⭐️ Reputation: 210
🛠 State: resolved
💼 Team: Mozilla
💵 Bounty: null
🕐 Submitted: 2025-06-03
Disclosed: 2025-07-29 14:43:32
📝 Summary: The report identifies a bypass vulnerability in the biography field on addons.allizom.org. Despite the application's policy against allowing links, it was possible to embed functional hyperlinks using protocol-relative URLs (//evil.com). This violation of the declared application policy was achieved by including an <a> tag with the protocol-relative URL.
📂 Report JSON File: 3175695
@hackeronereports
😁1