🎯 New Report #377565: Can view all username leaked in https://core.blockstack.org
🔺Severity: null
👽 Reporter: myskar
⭐️ Reputation: 1094
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2018-07-05
⏰ Disclosed: 2025-10-31 17:32:59
📝 Summary: null
📂 Report JSON File: 377565
@hackeronereports
🔺Severity: null
👽 Reporter: myskar
⭐️ Reputation: 1094
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2018-07-05
⏰ Disclosed: 2025-10-31 17:32:59
📝 Summary: null
📂 Report JSON File: 377565
@hackeronereports
🎯 New Report #716647: Invalidate active sessions after password change
🔺Severity: Low
👽 Reporter: droop3r
⭐️ Reputation: 251
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2019-10-17
⏰ Disclosed: 2025-10-31 17:32:49
📝 Summary: null
📂 Report JSON File: 716647
@hackeronereports
🔺Severity: Low
👽 Reporter: droop3r
⭐️ Reputation: 251
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2019-10-17
⏰ Disclosed: 2025-10-31 17:32:49
📝 Summary: null
📂 Report JSON File: 716647
@hackeronereports
🎯 New Report #910732: blockstack.org - is vulnerable to (CVE-2016-2183, CVE-2016-6329)
🔺Severity: None
👽 Reporter: 0x1 aulia
⭐️ Reputation: 93
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2020-06-29
⏰ Disclosed: 2025-10-31 17:32:21
📝 Summary: null
📂 Report JSON File: 910732
@hackeronereports
🔺Severity: None
👽 Reporter: 0x1 aulia
⭐️ Reputation: 93
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2020-06-29
⏰ Disclosed: 2025-10-31 17:32:21
📝 Summary: null
📂 Report JSON File: 910732
@hackeronereports
🎯 New Report #541760: Blockstack Browser For Mac leaks "Core API Password" to 3rd parties
🔺Severity: Low
👽 Reporter: frozensolid
⭐️ Reputation: 673
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2019-04-18
⏰ Disclosed: 2025-10-31 17:32:08
📝 Summary: null
📂 Report JSON File: 541760
@hackeronereports
🔺Severity: Low
👽 Reporter: frozensolid
⭐️ Reputation: 673
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2019-04-18
⏰ Disclosed: 2025-10-31 17:32:08
📝 Summary: null
📂 Report JSON File: 541760
@hackeronereports
🎯 New Report #3062299: Logout Bypass Vulnerability in Hiro.so
🔺Severity: Medium
👽 Reporter: anonymous--1000
⭐️ Reputation: 97
🛠 State: informative
💼 Team: Hiro
💵 Bounty: 150
🕐 Submitted: 2025-03-27
⏰ Disclosed: 2025-10-31 17:31:10
📝 Summary: null
📂 Report JSON File: 3062299
@hackeronereports
🔺Severity: Medium
👽 Reporter: anonymous--1000
⭐️ Reputation: 97
🛠 State: informative
💼 Team: Hiro
💵 Bounty: 150
🕐 Submitted: 2025-03-27
⏰ Disclosed: 2025-10-31 17:31:10
📝 Summary: null
📂 Report JSON File: 3062299
@hackeronereports
🎯 New Report #3243860: Microsoft `x-apikey` Exposed in Mozilla CI Public Logs
🔺Severity: Medium
👽 Reporter: xhacking z
⭐️ Reputation: 358
🛠 State: resolved
💼 Team: Mozilla
💵 Bounty: 200
🕐 Submitted: 2025-07-09
⏰ Disclosed: 2025-11-03 10:34:21
📝 Summary: A Microsoft telemetry API key (x-apikey) was found exposed in publicly accessible Mozilla CI logs. The key appeared in HTTP POST requests sent to Microsoft's telemetry endpoint during automated Firefox testing and was captured via mitmproxy logs. The security impact was considered minimal as the telemetry API key had limited functionality. The report was accepted and a bonus was paid as recognition of the reporter's efforts.
📂 Report JSON File: 3243860
@hackeronereports
🔺Severity: Medium
👽 Reporter: xhacking z
⭐️ Reputation: 358
🛠 State: resolved
💼 Team: Mozilla
💵 Bounty: 200
🕐 Submitted: 2025-07-09
⏰ Disclosed: 2025-11-03 10:34:21
📝 Summary: A Microsoft telemetry API key (x-apikey) was found exposed in publicly accessible Mozilla CI logs. The key appeared in HTTP POST requests sent to Microsoft's telemetry endpoint during automated Firefox testing and was captured via mitmproxy logs. The security impact was considered minimal as the telemetry API key had limited functionality. The report was accepted and a bonus was paid as recognition of the reporter's efforts.
📂 Report JSON File: 3243860
@hackeronereports
🎯 New Report #3371414: Improper Authorization Leads to Editor can toggle admin-only workspace features (Lovable Cloud)
🔺Severity: Low
👽 Reporter: d0maxploit
⭐️ Reputation: 114
🛠 State: resolved
💼 Team: Lovable VDP
💵 Bounty: null
🕐 Submitted: 2025-10-05
⏰ Disclosed: 2025-11-04 20:32:59
📝 Summary: A vulnerability was discovered where an account with the Editor role could call an API endpoint that disabled workspace-wide admin-only features. This was due to a lack of server-side role checks, allowing a vertical privilege escalation.
📂 Report JSON File: 3371414
@hackeronereports
🔺Severity: Low
👽 Reporter: d0maxploit
⭐️ Reputation: 114
🛠 State: resolved
💼 Team: Lovable VDP
💵 Bounty: null
🕐 Submitted: 2025-10-05
⏰ Disclosed: 2025-11-04 20:32:59
📝 Summary: A vulnerability was discovered where an account with the Editor role could call an API endpoint that disabled workspace-wide admin-only features. This was due to a lack of server-side role checks, allowing a vertical privilege escalation.
📂 Report JSON File: 3371414
@hackeronereports
🎯 New Report #3371448: Improper Authorization Leads to Editor can toggle admin-only workspace features (Lovable AI)
🔺Severity: Low
👽 Reporter: d0maxploit
⭐️ Reputation: 114
🛠 State: resolved
💼 Team: Lovable VDP
💵 Bounty: null
🕐 Submitted: 2025-10-05
⏰ Disclosed: 2025-11-04 22:54:23
📝 Summary: The API endpoint /workspaces/<WORKSPACE ID>/tool-preferences/ai gateway/enable did not enforce proper authorization checks. As a result, an account with the Editor role was able to disable the workspace-wide admin-only Lovable AI feature, which powers key AI functionalities across the workspace.
📂 Report JSON File: 3371448
@hackeronereports
🔺Severity: Low
👽 Reporter: d0maxploit
⭐️ Reputation: 114
🛠 State: resolved
💼 Team: Lovable VDP
💵 Bounty: null
🕐 Submitted: 2025-10-05
⏰ Disclosed: 2025-11-04 22:54:23
📝 Summary: The API endpoint /workspaces/<WORKSPACE ID>/tool-preferences/ai gateway/enable did not enforce proper authorization checks. As a result, an account with the Editor role was able to disable the workspace-wide admin-only Lovable AI feature, which powers key AI functionalities across the workspace.
📂 Report JSON File: 3371448
@hackeronereports
🎯 New Report #3355218: CVE-2025-10966: missing SFTP host verification with wolfSSH
🔺Severity: Low
👽 Reporter: giant anteater
⭐️ Reputation: 123
🛠 State: resolved
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-09-23
⏰ Disclosed: 2025-11-05 21:57:54
📝 Summary: null
📂 Report JSON File: 3355218
@hackeronereports
🔺Severity: Low
👽 Reporter: giant anteater
⭐️ Reputation: 123
🛠 State: resolved
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-09-23
⏰ Disclosed: 2025-11-05 21:57:54
📝 Summary: null
📂 Report JSON File: 3355218
@hackeronereports
🎯 New Report #3335709: SQL Injection in Django ORM via Unvalidated ` connector` in Q Objects
🔺Severity: Critical
👽 Reporter: cyberstan
⭐️ Reputation: 92
🛠 State: resolved
💼 Team: Django
💵 Bounty: null
🕐 Submitted: 2025-09-12
⏰ Disclosed: 2025-11-06 21:09:42
📝 Summary: A critical SQL injection vulnerability was discovered in the Django ORM's handling of Q objects. The internal WhereNode.as sql method used unsafe string formatting to inject the query connector, which could be controlled by an attacker through the connector key when creating a Q object. This allowed arbitrary SQL to be injected into the WHERE clause, bypassing the ORM's parameterization safeguards.
📂 Report JSON File: 3335709
@hackeronereports
🔺Severity: Critical
👽 Reporter: cyberstan
⭐️ Reputation: 92
🛠 State: resolved
💼 Team: Django
💵 Bounty: null
🕐 Submitted: 2025-09-12
⏰ Disclosed: 2025-11-06 21:09:42
📝 Summary: A critical SQL injection vulnerability was discovered in the Django ORM's handling of Q objects. The internal WhereNode.as sql method used unsafe string formatting to inject the query connector, which could be controlled by an attacker through the connector key when creating a Q object. This allowed arbitrary SQL to be injected into the WHERE clause, bypassing the ORM's parameterization safeguards.
📂 Report JSON File: 3335709
@hackeronereports
🎯 New Report #3369843: Low-privileged user can enable or disable Lovable AI for new projects in workspace
🔺Severity: Low
👽 Reporter: anxioussick
⭐️ Reputation: 129
🛠 State: resolved
💼 Team: Lovable VDP
💵 Bounty: null
🕐 Submitted: 2025-10-03
⏰ Disclosed: 2025-11-07 03:52:10
📝 Summary: A vulnerability was discovered that allowed low-privileged users to enable or disable Lovable AI for new projects in a workspace. The vulnerability was caused by improper authorization, which enabled low-privileged users to modify the Lovable AI settings by replaying certain API endpoints.
📂 Report JSON File: 3369843
@hackeronereports
🔺Severity: Low
👽 Reporter: anxioussick
⭐️ Reputation: 129
🛠 State: resolved
💼 Team: Lovable VDP
💵 Bounty: null
🕐 Submitted: 2025-10-03
⏰ Disclosed: 2025-11-07 03:52:10
📝 Summary: A vulnerability was discovered that allowed low-privileged users to enable or disable Lovable AI for new projects in a workspace. The vulnerability was caused by improper authorization, which enabled low-privileged users to modify the Lovable AI settings by replaying certain API endpoints.
📂 Report JSON File: 3369843
@hackeronereports
🎯 New Report #3378635: Unauthorized Password Reset Allows Account Takeover Across Tenant Boundaries
🔺Severity: High
👽 Reporter: mcdave
⭐️ Reputation: 107
🛠 State: resolved
💼 Team: lemlist
💵 Bounty: null
🕐 Submitted: 2025-10-10
⏰ Disclosed: 2025-11-07 09:33:24
📝 Summary: An authorization issue was discovered in the application that allowed a tenant admin to change the password of another user within the same tenant, including invited agency accounts. The victim had to first accept the invitation before the attacker could proceed. The issue could allow unintended account access within a shared tenant environment, but multi-factor authentication successfully prevented logins when enabled. The issue was reported to the vendor and addressed to ensure stricter access controls for user credential changes.
📂 Report JSON File: 3378635
@hackeronereports
🔺Severity: High
👽 Reporter: mcdave
⭐️ Reputation: 107
🛠 State: resolved
💼 Team: lemlist
💵 Bounty: null
🕐 Submitted: 2025-10-10
⏰ Disclosed: 2025-11-07 09:33:24
📝 Summary: An authorization issue was discovered in the application that allowed a tenant admin to change the password of another user within the same tenant, including invited agency accounts. The victim had to first accept the invitation before the attacker could proceed. The issue could allow unintended account access within a shared tenant environment, but multi-factor authentication successfully prevented logins when enabled. The issue was reported to the vendor and addressed to ensure stricter access controls for user credential changes.
📂 Report JSON File: 3378635
@hackeronereports
🎯 New Report #3414088: SMTP CRLF Command Injection in CURLOPT MAIL FROM and CURLOPT MAIL RCPT
🔺Severity: Medium
👽 Reporter: bau1u
⭐️ Reputation: 116
🛠 State: duplicate
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-11-06
⏰ Disclosed: 2025-11-10 10:39:03
📝 Summary: null
📂 Report JSON File: 3414088
@hackeronereports
🔺Severity: Medium
👽 Reporter: bau1u
⭐️ Reputation: 116
🛠 State: duplicate
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-11-06
⏰ Disclosed: 2025-11-10 10:39:03
📝 Summary: null
📂 Report JSON File: 3414088
@hackeronereports
🎯 New Report #3417428: libcurl MQTT `CURLOPT POSTFIELDSIZE LARGE` overflow leads to immediate DoS
🔺Severity: Medium
👽 Reporter: jiyong
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-11-09
⏰ Disclosed: 2025-11-10 15:00:34
📝 Summary: null
📂 Report JSON File: 3417428
@hackeronereports
🔺Severity: Medium
👽 Reporter: jiyong
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-11-09
⏰ Disclosed: 2025-11-10 15:00:34
📝 Summary: null
📂 Report JSON File: 3417428
@hackeronereports
🎯 New Report #3079738: Two click Account Takeover
🔺Severity: High
👽 Reporter: fr4via
⭐️ Reputation: 11240
🛠 State: resolved
💼 Team: Basecamp
💵 Bounty: null
🕐 Submitted: 2025-04-06
⏰ Disclosed: 2025-11-11 09:14:15
📝 Summary: A vulnerability was discovered in the HEY Email Android application that allowed for a two-click account takeover. Improper handling of incoming deeplinks led to the application's authorization bearer token being sent to an attacker-controlled server if the user could be tricked into clicking a link and then performing an Undo action.
📂 Report JSON File: 3079738
@hackeronereports
🔺Severity: High
👽 Reporter: fr4via
⭐️ Reputation: 11240
🛠 State: resolved
💼 Team: Basecamp
💵 Bounty: null
🕐 Submitted: 2025-04-06
⏰ Disclosed: 2025-11-11 09:14:15
📝 Summary: A vulnerability was discovered in the HEY Email Android application that allowed for a two-click account takeover. Improper handling of incoming deeplinks led to the application's authorization bearer token being sent to an attacker-controlled server if the user could be tricked into clicking a link and then performing an Undo action.
📂 Report JSON File: 3079738
@hackeronereports
🎯 New Report #3419636: Authentication Token Theft via Open Redirect in Callback URL Parameter
🔺Severity: Critical
👽 Reporter: sle3pyhead
⭐️ Reputation: 96
🛠 State: resolved
💼 Team: lemlist
💵 Bounty: null
🕐 Submitted: 2025-11-11
⏰ Disclosed: 2025-11-14 15:26:16
📝 Summary: A vulnerability was identified in the email signup flow of a website that enabled authentication token theft through manipulation of the callback URL parameter. The vulnerability occurred when an attacker modified the callbackUrl parameter during the email signup process to point to an attacker-controlled domain. When a victim completed the email verification process by clicking the verification link, they were redirected to the malicious domain along with their authentication tokens. The redirection happened automatically as part of the normal signup flow. The vulnerability was caused by insufficient validation of the callback URL parameter and leveraged the trust users place in legitimate verification emails.
📂 Report JSON File: 3419636
@hackeronereports
🔺Severity: Critical
👽 Reporter: sle3pyhead
⭐️ Reputation: 96
🛠 State: resolved
💼 Team: lemlist
💵 Bounty: null
🕐 Submitted: 2025-11-11
⏰ Disclosed: 2025-11-14 15:26:16
📝 Summary: A vulnerability was identified in the email signup flow of a website that enabled authentication token theft through manipulation of the callback URL parameter. The vulnerability occurred when an attacker modified the callbackUrl parameter during the email signup process to point to an attacker-controlled domain. When a victim completed the email verification process by clicking the verification link, they were redirected to the malicious domain along with their authentication tokens. The redirection happened automatically as part of the normal signup flow. The vulnerability was caused by insufficient validation of the callback URL parameter and leveraged the trust users place in legitimate verification emails.
📂 Report JSON File: 3419636
@hackeronereports
🎯 New Report #3382796: Responsible disclosure - public S3 bucket exposing JSON/config files
🔺Severity: Low
👽 Reporter: xtawb
⭐️ Reputation: 29
🛠 State: resolved
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-10-14
⏰ Disclosed: 2025-11-14 19:25:28
📝 Summary: A publicly listable S3 bucket was discovered, exposing various JSON and configuration files. The bucket listing and file metadata were retrievable without authentication.
📂 Report JSON File: 3382796
@hackeronereports
🔺Severity: Low
👽 Reporter: xtawb
⭐️ Reputation: 29
🛠 State: resolved
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-10-14
⏰ Disclosed: 2025-11-14 19:25:28
📝 Summary: A publicly listable S3 bucket was discovered, exposing various JSON and configuration files. The bucket listing and file metadata were retrievable without authentication.
📂 Report JSON File: 3382796
@hackeronereports
🎯 New Report #3427670: Double-free vulnerability in libcurl with rustls via NoServerCertVerifier condition leads to application crash
🔺Severity: null
👽 Reporter: xkernel
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-11-16
⏰ Disclosed: 2025-11-16 22:40:20
📝 Summary: null
📂 Report JSON File: 3427670
@hackeronereports
🔺Severity: null
👽 Reporter: xkernel
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-11-16
⏰ Disclosed: 2025-11-16 22:40:20
📝 Summary: null
📂 Report JSON File: 3427670
@hackeronereports
🎯 New Report #3417162: Authentication Bypass in Subscription Management Endpoint
🔺Severity: Critical
👽 Reporter: 0hmz
⭐️ Reputation: 135
🛠 State: resolved
💼 Team: lemlist
💵 Bounty: null
🕐 Submitted: 2025-11-09
⏰ Disclosed: 2025-11-17 13:08:04
📝 Summary: A vulnerability was identified in the subscription management functionality that allowed unauthorized access to customer billing information. The issue stemmed from insufficient authentication and authorization controls on an API endpoint. The vulnerability was classified as an Insecure Direct Object Reference (IDOR) vulnerability, where customer identifiers could be manipulated to access other users' data. The vulnerability has been promptly addressed and fixed by the development team.
📂 Report JSON File: 3417162
@hackeronereports
🔺Severity: Critical
👽 Reporter: 0hmz
⭐️ Reputation: 135
🛠 State: resolved
💼 Team: lemlist
💵 Bounty: null
🕐 Submitted: 2025-11-09
⏰ Disclosed: 2025-11-17 13:08:04
📝 Summary: A vulnerability was identified in the subscription management functionality that allowed unauthorized access to customer billing information. The issue stemmed from insufficient authentication and authorization controls on an API endpoint. The vulnerability was classified as an Insecure Direct Object Reference (IDOR) vulnerability, where customer identifiers could be manipulated to access other users' data. The vulnerability has been promptly addressed and fixed by the development team.
📂 Report JSON File: 3417162
@hackeronereports
❤1
🎯 New Report #3027461: Bypass of Cloudflare's Cache Keys and WAF via header overflow
🔺Severity: High
👽 Reporter: david96
⭐️ Reputation: 3516
🛠 State: resolved
💼 Team: Cloudflare Public Bug Bounty
💵 Bounty: null
🕐 Submitted: 2025-03-12
⏰ Disclosed: 2025-11-18 08:08:43
📝 Summary: A limitation in the HTTP request header parsing in Front Line (FL) processing enabled attackers to bypass defined rulesets. The maximum amount of headers being parsed by openresty was 100 HTTP headers including internal ones. This problem applied to any ruleset on HTTP headers. Attackers were able to bypass WAF rules and perform cache forcing/poisoning. A global rule was implemented to block when too many headers were provided, which was recommended to be enabled. The length problem of parsed HTTP headers was mitigated with the rollout of the new Front Line implementation.
📂 Report JSON File: 3027461
@hackeronereports
🔺Severity: High
👽 Reporter: david96
⭐️ Reputation: 3516
🛠 State: resolved
💼 Team: Cloudflare Public Bug Bounty
💵 Bounty: null
🕐 Submitted: 2025-03-12
⏰ Disclosed: 2025-11-18 08:08:43
📝 Summary: A limitation in the HTTP request header parsing in Front Line (FL) processing enabled attackers to bypass defined rulesets. The maximum amount of headers being parsed by openresty was 100 HTTP headers including internal ones. This problem applied to any ruleset on HTTP headers. Attackers were able to bypass WAF rules and perform cache forcing/poisoning. A global rule was implemented to block when too many headers were provided, which was recommended to be enabled. The length problem of parsed HTTP headers was mitigated with the rollout of the new Front Line implementation.
📂 Report JSON File: 3027461
@hackeronereports
🎯 New Report #3431180: Double free in tool ssls load()
🔺Severity: null
👽 Reporter: xkernel
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-11-18
⏰ Disclosed: 2025-11-18 23:32:00
📝 Summary: null
📂 Report JSON File: 3431180
@hackeronereports
🔺Severity: null
👽 Reporter: xkernel
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-11-18
⏰ Disclosed: 2025-11-18 23:32:00
📝 Summary: null
📂 Report JSON File: 3431180
@hackeronereports