Hackerone Reports
223 subscribers
741 links
Last Check 2026-09-18 12:45:01
Download Telegram
🎯 New Report #2280279: total Failure of password protection while extracting seed phrase! increases attack surface area for scammers
🔺Severity: Medium
👽 Reporter: bug vs me
⭐️ Reputation: 2580
🛠 State: resolved
💼 Team: MetaMask
💵 Bounty: 3500
🕐 Submitted: 2023-12-10
Disclosed: 2025-07-31 19:36:43
📝 Summary: The MetaMask browser extension UI was able to access a user's seed phrase without requiring password confirmation, which violated expected security boundaries between the UI and background process. The issue was resolved in MetaMask Extension version 11.7.1, which now enforces password confirmation before any UI code can access the wallet's seed phrase.
📂 Report JSON File: 2280279
@hackeronereports
🎯 New Report #3279508: Unauthorized Disclosure of Private Emails via WakaTime Private Leaderboards
🔺Severity: Medium
👽 Reporter: ctrl cipher
⭐️ Reputation: 201
🛠 State: resolved
💼 Team: WakaTime
💵 Bounty: null
🕐 Submitted: 2025-07-31
Disclosed: 2025-08-03 03:23:03
📝 Summary: The vulnerability allowed unauthorized disclosure of private email addresses of WakaTime users through the private leaderboards feature. The email addresses were exposed to leaderboard creators and members, even when the users had not chosen to make their emails public.
📂 Report JSON File: 3279508
@hackeronereports
🎯 New Report #3287060: Double Clickjacking Attack on WakaTime OAuth Authorization Flow at https://wakatime.com/oauth/authorize
🔺Severity: Medium
👽 Reporter: zeesozee
⭐️ Reputation: 178
🛠 State: resolved
💼 Team: WakaTime
💵 Bounty: null
🕐 Submitted: 2025-08-05
Disclosed: 2025-08-05 23:25:44
📝 Summary: The WakaTime OAuth authorization flow was vulnerable to a double-clickjacking attack. The attack allowed an attacker to trick users into unknowingly clicking the "Connect my WakaTime account" button in the consent dialog, enabling the attacker to register an OAuth application, capture the authorization code, and exchange it for an access token. This granted the attacker full access to defined permissions on behalf of the victim.
📂 Report JSON File: 3287060
@hackeronereports
🎯 New Report #3290630: Sample report: Denial of service
🔺Severity: None
👽 Reporter: ghbountyocto
⭐️ Reputation: 121
🛠 State: resolved
💼 Team: GitHub
💵 Bounty: null
🕐 Submitted: 2025-08-07
Disclosed: 2025-08-07 16:40:12
📝 Summary: The denial of service vulnerability was identified in the system. The vulnerability could have allowed an attacker to disrupt the availability of the system by exhausting its resources.
📂 Report JSON File: 3290630
@hackeronereports
🎯 New Report #3174987: Man-in-the-middle through broken SSL certificate verification
🔺Severity: Medium
👽 Reporter: kinnay
⭐️ Reputation: 724
🛠 State: resolved
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2025-06-06
Disclosed: 2025-08-08 01:22:09
📝 Summary: The vulnerability allowed an attacker to perform a man-in-the-middle attack by bypassing SSL certificate verification.
📂 Report JSON File: 3174987
@hackeronereports
🎯 New Report #3221185: Exceed the maximum number of subscribers using Race Condition
🔺Severity: Low
👽 Reporter: q11x
⭐️ Reputation: 411
🛠 State: resolved
💼 Team: SingleStore
💵 Bounty: null
🕐 Submitted: 2025-06-25
Disclosed: 2025-08-12 19:52:29
📝 Summary: A race condition vulnerability was discovered in the SingleStore control panel that allowed bypassing the maximum limit of five subscribers for alerts. The issue was patched and deployed to production.
📂 Report JSON File: 3221185
@hackeronereports
🎯 New Report #3219944: IDOR - Scheduled data leak to other accounts By "projectID"
🔺Severity: Medium
👽 Reporter: q11x
⭐️ Reputation: 411
🛠 State: resolved
💼 Team: SingleStore
💵 Bounty: null
🕐 Submitted: 2025-06-25
Disclosed: 2025-08-12 19:47:48
📝 Summary: The Insecure Direct Object Reference (IDOR) vulnerability was discovered in the GetNotebookScheduledPaginatedJobs endpoint on backend.singlestore.com. The API failed to verify the requestor's permission to access the specified project, allowing an authenticated user to access scheduled job information belonging to other users' projects by modifying the projectID parameter. The vulnerability exposed sensitive information such as database names, notebook paths, scheduling details, and infrastructure information.
📂 Report JSON File: 3219944
@hackeronereports
🎯 New Report #3113398: Internal Access to Hackerone confluence Docs
🔺Severity: High
👽 Reporter: madara
⭐️ Reputation: 3339
🛠 State: resolved
💼 Team: HackerOne
💵 Bounty: $12,500
🕐 Submitted: 2025-04-26
Disclosed: 2025-08-13 22:05:42
📝 Summary: During testing on ticketing platforms, it was discovered that HackerOne's support ticket system was misconfigured, introducing a security risk. The email ███████ was enabled to create and manage tickets on the support platform, allowing an attacker to abuse the ticketing system to register users on third-party platforms impersonating the domain @hackerone.com.
📂 Report JSON File: 3113398
@hackeronereports
🔥1
🎯 New Report #3250315: █.8x8.vc/index.js: Exposed Google Maps API Key Allowing Potential Abuse of Paid Services
🔺Severity: Medium
👽 Reporter: abdallasamir12
⭐️ Reputation: 117
🛠 State: resolved
💼 Team: 8x8 Bounty
💵 Bounty: 500
🕐 Submitted: 2025-07-13
Disclosed: 2025-08-14 01:30:47
📝 Summary: The Google Maps API key was inadvertently exposed in client-side code, allowing potential unauthorized access to some Google Maps services. The issue was promptly addressed by implementing appropriate API key restrictions where feasible.
📂 Report JSON File: 3250315
@hackeronereports
🎯 New Report #1848940: URL Path Manipulation Enables Cache Poisoning of Amazon Affiliate Products in Shopify Linkpop
🔺Severity: Low
👽 Reporter: saltymermaid
⭐️ Reputation: 1020
🛠 State: resolved
💼 Team: Shopify
💵 Bounty: 500
🕐 Submitted: 2023-01-27
Disclosed: 2025-08-14 15:14:43
📝 Summary: The Shopify Linkpop service was found vulnerable to a cache poisoning issue that allowed attackers to manipulate the display of Amazon affiliate products. By crafting malicious URLs, attackers could trick victims into linking to the attacker's products instead of the intended ones. This vulnerability was not fixed, as the Linkpop service was scheduled for decommissioning.
📂 Report JSON File: 1848940
@hackeronereports
🎯 New Report #3217840: Remote Code Execution in Amazon MWAA due to outdated Apache Airflow version
🔺Severity: None
👽 Reporter: ricardojoserf
⭐️ Reputation: 100
🛠 State: informative
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-06-24
Disclosed: 2025-08-14 14:55:11
📝 Summary: null
📂 Report JSON File: 3217840
@hackeronereports
🎯 New Report #3020733: Email Verification Bypass via Race Condition
🔺Severity: None
👽 Reporter: sijojohnson
⭐️ Reputation: 87
🛠 State: informative
💼 Team: Malwarebytes
💵 Bounty: null
🕐 Submitted: 2025-03-02
Disclosed: 2025-08-15 14:55:42
📝 Summary: null
📂 Report JSON File: 3020733
@hackeronereports
🎯 New Report #3269777: Replayable Password Change Request Across Sessions.
🔺Severity: None
👽 Reporter: mantu1738
⭐️ Reputation: 102
🛠 State: informative
💼 Team: Malwarebytes
💵 Bounty: null
🕐 Submitted: 2025-07-24
Disclosed: 2025-08-15 14:44:47
📝 Summary: null
📂 Report JSON File: 3269777
@hackeronereports
🎯 New Report #1874836: Rails Debug Mode Enabled On ( https://44.208.145.207/testrail/files.md5 )
🔺Severity: Low
👽 Reporter: tarun sec
⭐️ Reputation: 286
🛠 State: resolved
💼 Team: Malwarebytes
💵 Bounty: null
🕐 Submitted: 2023-02-15
Disclosed: 2025-08-15 14:24:06
📝 Summary: Summary:

A Ruby on Rails web application running in development mode was identified on a Malwarebytes server. This exposed sensitive system information, including details about middleware components and application root paths, which should not have been accessible in a production environment.
📂 Report JSON File: 1874836
@hackeronereports
🎯 New Report #1030042: No SPF/DMARC records on mb-cosmos.com
🔺Severity: Medium
👽 Reporter: assassin marcos
⭐️ Reputation: 3549
🛠 State: resolved
💼 Team: Malwarebytes
💵 Bounty: null
🕐 Submitted: 2020-11-09
Disclosed: 2025-08-18 13:58:49
📝 Summary: The domain mb-cosmos.com lacked SPF and DMARC records, allowing email spoofing. Emails appeared to originate from the domain without authentication. This vulnerability was reported as a security issue.
📂 Report JSON File: 1030042
@hackeronereports
🌚1
🎯 New Report #2718253: Email verification bypass via request to endpoint "accounts.insightly.com/signup/provisionuser"
🔺Severity: Critical
👽 Reporter: akostak
⭐️ Reputation: 163
🛠 State: resolved
💼 Team: Insightly
💵 Bounty: null
🕐 Submitted: 2024-09-15
Disclosed: 2025-08-18 19:55:35
📝 Summary: The vulnerability allowed bypassing email verification when creating a new Insightly account. The vulnerability existed in the "EmailAddress" parameter of the member creation endpoint. By modifying the parameter, an attacker could create a new account using any email address, including those of existing users, effectively taking over their accounts.
📂 Report JSON File: 2718253
@hackeronereports
🔥1
🎯 New Report #3304704: Invalid
🔺Severity: Low
👽 Reporter: pashaaaaaaaa
⭐️ Reputation: 95
🛠 State: informative
💼 Team: WakaTime
💵 Bounty: null
🕐 Submitted: 2025-08-19
Disclosed: 2025-08-19 23:05:09
📝 Summary: null
📂 Report JSON File: 3304704
@hackeronereports
🎯 New Report #3086301: Prompt Injection via GitHub Patch in Brave AI Chat (Leo)
🔺Severity: High
👽 Reporter: stellersjay
⭐️ Reputation: 152
🛠 State: informative
💼 Team: Brave Software
💵 Bounty: null
🕐 Submitted: 2025-04-09
Disclosed: 2025-08-22 20:33:25
📝 Summary: null
📂 Report JSON File: 3086301
@hackeronereports
💩1
🎯 New Report #3008066: Stored XSS in AREA tutorials
🔺Severity: High
👽 Reporter: who am i
⭐️ Reputation: 103
🛠 State: resolved
💼 Team: Autodesk
💵 Bounty: null
🕐 Submitted: 2025-02-23
Disclosed: 2025-08-25 12:39:06
📝 Summary: A stored cross-site scripting (XSS) vulnerability was discovered in the AREA tutorials feature. The vulnerability could have allowed an attacker to inject malicious JavaScript code when publishing a tutorial. The vulnerability was reported and fixed by Autodesk.
📂 Report JSON File: 3008066
@hackeronereports
🎯 New Report #3287396: AWS | Self Registration Internal LibreChat : Access to internal/proprietary LLMs
🔺Severity: Low
👽 Reporter: notnotnotveg
⭐️ Reputation: 422
🛠 State: resolved
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-08-05
Disclosed: 2025-08-25 23:54:59
📝 Summary: null
📂 Report JSON File: 3287396
@hackeronereports
🎯 New Report #3302484: CWE-195 in ExternalMemoryAccounter::Increase()
🔺Severity: null
👽 Reporter: codingthunder
⭐️ Reputation: 100
🛠 State: informative
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2025-08-18
Disclosed: 2025-08-26 06:11:30
📝 Summary: null
📂 Report JSON File: 3302484
@hackeronereports