Hackerone Reports
227 subscribers
743 links
Last Check 2026-09-20 00:45:01
Download Telegram
🎯 New Report #3104356: Blu-ray Disc Java Sandbox Escape via two vulnerabilities
🔺Severity: Medium
👽 Reporter: theflow0
⭐️ Reputation: 657
🛠 State: resolved
💼 Team: PlayStation
💵 Bounty: 5000
🕐 Submitted: 2025-04-22
Disclosed: 2025-10-18 00:35:23
📝 Summary: Two vulnerabilities in Blu-ray Disc Java (bd-j) related to the Inter-Xlet Communication (Ixc) implementation were discovered. The first vulnerability allowed invoking methods in privileged context by registering a remote object that implements an interface extending java.rmi.Remote. The second vulnerability enabled privileged method invocation by setting a custom method in the stub class generated for remote object registration. Together, these vulnerabilities could be exploited to disable the Java sandbox.
📂 Report JSON File: 3104356
@hackeronereports
🎯 New Report #3058919: Application Level DoS - Large Markdown Payload in Reply Section Leading to Resource Exhaustion
🔺Severity: High
👽 Reporter: theteatoast
⭐️ Reputation: 356
🛠 State: resolved
💼 Team: Discourse
💵 Bounty: null
🕐 Submitted: 2025-03-25
Disclosed: 2025-10-18 16:47:02
📝 Summary: A Denial of Service (DoS) vulnerability was identified in the reply section of the web application. Submitting an excessively large markup payload (approximately 800,000 characters) resulted in the server taking 30 seconds to respond before returning an HTTP/2 502 Bad Gateway error, indicating potential resource exhaustion or backend service failure.
📂 Report JSON File: 3058919
@hackeronereports
🎯 New Report #3383095: DNS Rebinding Attack
🔺Severity: Critical
👽 Reporter: newby99
⭐️ Reputation: 178
🛠 State: informative
💼 Team: arkadiyt-projects
💵 Bounty: null
🕐 Submitted: 2025-10-14
Disclosed: 2025-10-19 21:33:19
📝 Summary: null
📂 Report JSON File: 3383095
@hackeronereports
🎯 New Report #3384150: Arbitrary File Write
🔺Severity: High
👽 Reporter: newby99
⭐️ Reputation: 178
🛠 State: resolved
💼 Team: arkadiyt-projects
💵 Bounty: null
🕐 Submitted: 2025-10-14
Disclosed: 2025-10-19 21:19:02
📝 Summary: A path traversal vulnerability was discovered in the protodump tool. The vulnerability allowed for arbitrary file writes outside the intended output directory due to insufficient validation of the go package option extracted from embedded protobuf descriptors. The Filename() function extracted the go package option without sanitization, enabling an attacker to create a malicious binary with a crafted go package value containing path traversal sequences. When the user ran protodump on this binary, the tool wrote the extracted proto file to an arbitrary location on the filesystem.
📂 Report JSON File: 3384150
@hackeronereports
🎯 New Report #3329361: 2FA bypass possible on https://authsvc.singlestore.com
🔺Severity: Medium
👽 Reporter: axolot23
⭐️ Reputation: 113
🛠 State: resolved
💼 Team: SingleStore
💵 Bounty: null
🕐 Submitted: 2025-09-06
Disclosed: 2025-10-22 06:44:27
📝 Summary: A vulnerability was discovered that allowed the 2FA authentication mechanism to be bypassed completely. An attacker could access the victim's account by only knowing the email address and password, without requiring the 2FA code.
📂 Report JSON File: 3329361
@hackeronereports
🎯 New Report #3091390: Reflected Cross-Site Scripting (XSS) in Revive Adserver 5.5.2
🔺Severity: Medium
👽 Reporter: env bak
⭐️ Reputation: 104
🛠 State: resolved
💼 Team: Revive Adserver
💵 Bounty: null
🕐 Submitted: 2025-04-14
Disclosed: 2025-10-22 09:54:05
📝 Summary: null
📂 Report JSON File: 3091390
@hackeronereports
🎯 New Report #3393539: Memory leak in Curl auth create ntlm type3 message
🔺Severity: Low
👽 Reporter: tjbecker theori
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-10-21
Disclosed: 2025-10-28 14:48:40
📝 Summary: null
📂 Report JSON File: 3393539
@hackeronereports
🎯 New Report #268221: No Confirmation Email For Email Change
🔺Severity: Low
👽 Reporter: craxermgr
⭐️ Reputation: 105
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2017-09-14
Disclosed: 2025-10-31 17:38:56
📝 Summary: null
📂 Report JSON File: 268221
@hackeronereports
🎯 New Report #268224: Information Disclosure
🔺Severity: Medium
👽 Reporter: craxermgr
⭐️ Reputation: 105
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2017-09-14
Disclosed: 2025-10-31 17:34:26
📝 Summary: null
📂 Report JSON File: 268224
@hackeronereports
🎯 New Report #300164: REDIRECTION VULNERABILITY/HOST HEADER INJECTION VULNERABILITY
🔺Severity: Medium
👽 Reporter: vyshnav nk
⭐️ Reputation: 50
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2017-12-23
Disclosed: 2025-10-31 17:33:52
📝 Summary: null
📂 Report JSON File: 300164
@hackeronereports
🎯 New Report #304073: Missing restriction on string size of Full Name at browser.blockstack.org
🔺Severity: null
👽 Reporter: myskar
⭐️ Reputation: 1094
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2018-01-11
Disclosed: 2025-10-31 17:33:31
📝 Summary: null
📂 Report JSON File: 304073
@hackeronereports
🎯 New Report #377565: Can view all username leaked in https://core.blockstack.org
🔺Severity: null
👽 Reporter: myskar
⭐️ Reputation: 1094
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2018-07-05
Disclosed: 2025-10-31 17:32:59
📝 Summary: null
📂 Report JSON File: 377565
@hackeronereports
🎯 New Report #716647: Invalidate active sessions after password change
🔺Severity: Low
👽 Reporter: droop3r
⭐️ Reputation: 251
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2019-10-17
Disclosed: 2025-10-31 17:32:49
📝 Summary: null
📂 Report JSON File: 716647
@hackeronereports
🎯 New Report #910732: blockstack.org - is vulnerable to (CVE-2016-2183, CVE-2016-6329)
🔺Severity: None
👽 Reporter: 0x1 aulia
⭐️ Reputation: 93
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2020-06-29
Disclosed: 2025-10-31 17:32:21
📝 Summary: null
📂 Report JSON File: 910732
@hackeronereports
🎯 New Report #541760: Blockstack Browser For Mac leaks "Core API Password" to 3rd parties
🔺Severity: Low
👽 Reporter: frozensolid
⭐️ Reputation: 673
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2019-04-18
Disclosed: 2025-10-31 17:32:08
📝 Summary: null
📂 Report JSON File: 541760
@hackeronereports
🎯 New Report #3062299: Logout Bypass Vulnerability in Hiro.so
🔺Severity: Medium
👽 Reporter: anonymous--1000
⭐️ Reputation: 97
🛠 State: informative
💼 Team: Hiro
💵 Bounty: 150
🕐 Submitted: 2025-03-27
Disclosed: 2025-10-31 17:31:10
📝 Summary: null
📂 Report JSON File: 3062299
@hackeronereports
🎯 New Report #3243860: Microsoft `x-apikey` Exposed in Mozilla CI Public Logs
🔺Severity: Medium
👽 Reporter: xhacking z
⭐️ Reputation: 358
🛠 State: resolved
💼 Team: Mozilla
💵 Bounty: 200
🕐 Submitted: 2025-07-09
Disclosed: 2025-11-03 10:34:21
📝 Summary: A Microsoft telemetry API key (x-apikey) was found exposed in publicly accessible Mozilla CI logs. The key appeared in HTTP POST requests sent to Microsoft's telemetry endpoint during automated Firefox testing and was captured via mitmproxy logs. The security impact was considered minimal as the telemetry API key had limited functionality. The report was accepted and a bonus was paid as recognition of the reporter's efforts.
📂 Report JSON File: 3243860
@hackeronereports
🎯 New Report #3371414: Improper Authorization Leads to Editor can toggle admin-only workspace features (Lovable Cloud)
🔺Severity: Low
👽 Reporter: d0maxploit
⭐️ Reputation: 114
🛠 State: resolved
💼 Team: Lovable VDP
💵 Bounty: null
🕐 Submitted: 2025-10-05
Disclosed: 2025-11-04 20:32:59
📝 Summary: A vulnerability was discovered where an account with the Editor role could call an API endpoint that disabled workspace-wide admin-only features. This was due to a lack of server-side role checks, allowing a vertical privilege escalation.
📂 Report JSON File: 3371414
@hackeronereports
🎯 New Report #3371448: Improper Authorization Leads to Editor can toggle admin-only workspace features (Lovable AI)
🔺Severity: Low
👽 Reporter: d0maxploit
⭐️ Reputation: 114
🛠 State: resolved
💼 Team: Lovable VDP
💵 Bounty: null
🕐 Submitted: 2025-10-05
Disclosed: 2025-11-04 22:54:23
📝 Summary: The API endpoint /workspaces/<WORKSPACE ID>/tool-preferences/ai gateway/enable did not enforce proper authorization checks. As a result, an account with the Editor role was able to disable the workspace-wide admin-only Lovable AI feature, which powers key AI functionalities across the workspace.
📂 Report JSON File: 3371448
@hackeronereports
🎯 New Report #3355218: CVE-2025-10966: missing SFTP host verification with wolfSSH
🔺Severity: Low
👽 Reporter: giant anteater
⭐️ Reputation: 123
🛠 State: resolved
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-09-23
Disclosed: 2025-11-05 21:57:54
📝 Summary: null
📂 Report JSON File: 3355218
@hackeronereports
🎯 New Report #3335709: SQL Injection in Django ORM via Unvalidated ` connector` in Q Objects
🔺Severity: Critical
👽 Reporter: cyberstan
⭐️ Reputation: 92
🛠 State: resolved
💼 Team: Django
💵 Bounty: null
🕐 Submitted: 2025-09-12
Disclosed: 2025-11-06 21:09:42
📝 Summary: A critical SQL injection vulnerability was discovered in the Django ORM's handling of Q objects. The internal WhereNode.as sql method used unsafe string formatting to inject the query connector, which could be controlled by an attacker through the connector key when creating a Q object. This allowed arbitrary SQL to be injected into the WHERE clause, bypassing the ORM's parameterization safeguards.
📂 Report JSON File: 3335709
@hackeronereports