{
  "schemaVersion": "1.0",
  "datasetVersion": "2026-08-22.1",
  "retrievedAt": "2026-08-22T19:49:53Z",
  "pagination": {
    "page": 1,
    "pageSize": 242,
    "total": 242,
    "next": null
  },
  "items": [
    {
      "id": "report:bugcrowd-daa0f9f3-039b-4c2b-b9ca-52c83f1b72ad",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-daa0f9f3-039b-4c2b-b9ca-52c83f1b72ad/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-daa0f9f3-039b-4c2b-b9ca-52c83f1b72ad",
      "record": {
        "id": "bugcrowd-daa0f9f3-039b-4c2b-b9ca-52c83f1b72ad",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "daa0f9f3-039b-4c2b-b9ca-52c83f1b72ad",
        "sourceUrl": "https://bugcrowd.com/disclosures/2b1df6dc-0ea2-42ee-a16a-9bbfc33e151a/unauthenticated-error-based-sql-injection-via-post-parameter-name-in-api-experiment-answer-new",
        "title": "Unauthenticated Error-Based SQL Injection via POST Parameter Name in /api/experiment/answer/new/",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "iaramsri",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-08-20",
        "submittedAt": "2026-08-11",
        "target": "https://nasa.gov",
        "vulnerabilityClass": "injection",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-50f94455-f4e2-4c16-8926-dded06fc7c0d",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-50f94455-f4e2-4c16-8926-dded06fc7c0d/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-50f94455-f4e2-4c16-8926-dded06fc7c0d",
      "record": {
        "id": "bugcrowd-50f94455-f4e2-4c16-8926-dded06fc7c0d",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "50f94455-f4e2-4c16-8926-dded06fc7c0d",
        "sourceUrl": "https://bugcrowd.com/disclosures/e7ef226d-895b-4cfa-859a-59f83475ee60/unauthenticated-remote-code-execution-in-nasa-ammos-ait-gui-2-5-0-via-tlm-query-file-write-chained-to-script-run-code-execution",
        "title": "Unauthenticated Remote Code Execution in NASA AMMOS AIT-GUI 2.5.0 via /tlm/query file write chained to /script/run code execution",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "ward0",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-08-20",
        "submittedAt": "2026-06-14",
        "target": "https://nasa.gov",
        "vulnerabilityClass": "code-execution",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-3421c4d6-f05c-4bfc-b24c-3f451140c18a",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-3421c4d6-f05c-4bfc-b24c-3f451140c18a/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-3421c4d6-f05c-4bfc-b24c-3f451140c18a",
      "record": {
        "id": "bugcrowd-3421c4d6-f05c-4bfc-b24c-3f451140c18a",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "3421c4d6-f05c-4bfc-b24c-3f451140c18a",
        "sourceUrl": "https://bugcrowd.com/disclosures/cc46ad29-f297-4847-abcd-9f5da5a85621/unauthorized-access-to-ci-cd-infrastructure-and-project-secrets-via-compromised-gitlab-runner-token",
        "title": "Unauthorized Access to CI/CD Infrastructure and Project Secrets via Compromised GitLab Runner Token",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "oguzhan_00",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-08-20",
        "submittedAt": "2026-05-06",
        "target": "https://nasa.gov",
        "vulnerabilityClass": "data-exposure",
        "hunterAngle": "Identify the intended audience and the narrowest unauthorized observer. Use controlled records, distinguish metadata from secret material, and quantify the repeatable exposure boundary.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-b2e0b5f4-a859-4c25-84bf-1d877b9450a3",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-b2e0b5f4-a859-4c25-84bf-1d877b9450a3/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-b2e0b5f4-a859-4c25-84bf-1d877b9450a3",
      "record": {
        "id": "bugcrowd-b2e0b5f4-a859-4c25-84bf-1d877b9450a3",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "b2e0b5f4-a859-4c25-84bf-1d877b9450a3",
        "sourceUrl": "https://bugcrowd.com/disclosures/5d10a6d3-734e-401d-8871-b141de740a46/urgent-critical-data-breach-cross-user-phi-pii-leakage-via-prompt-injection-non-malicious-discovery",
        "title": "URGENT: CRITICAL DATA BREACH - Cross-User PHI/PII Leakage via Prompt Injection - Non-malicious discovery",
        "program": "OpenAI",
        "programUrl": "https://bugcrowd.com/engagements/openai",
        "reporter": "Teringette-adamuzonyi",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-08-19",
        "submittedAt": "2026-05-06",
        "target": "ChatGPT",
        "vulnerabilityClass": "injection",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:research-kettle-http-terminator",
      "url": "https://vulns.co/api/v1/reports/research-kettle-http-terminator/",
      "webUrl": "https://vulns.co/reports/#report-research-kettle-http-terminator",
      "record": {
        "id": "research-kettle-http-terminator",
        "source": "researcher",
        "sourceLabel": "PortSwigger Research",
        "sourceType": "technique-research",
        "sourceUrl": "https://portswigger.net/research/can-ai-do-novel-security-research",
        "title": "Can AI do novel security research? Meet the HTTP Terminator",
        "program": "HTTP desynchronization research",
        "reporter": "James Kettle",
        "severityLabel": "Technique research",
        "severitySystem": "Publication type, not severity",
        "severityBasis": "not-severity",
        "disclosedAt": "2026-08-05",
        "vulnerabilityClass": "request-boundary",
        "publishedOutcome": "The abstract states affected categories but no universal severity or bounty amount.",
        "hunterAngle": "Keep reusable detection, replay, and evidence collection deterministic; reserve agent judgment for hypotheses that need human review.",
        "reviewStatus": "canonical-source-reviewed"
      }
    },
    {
      "id": "report:hackerone-3782701",
      "url": "https://vulns.co/api/v1/reports/hackerone-3782701/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3782701",
      "record": {
        "id": "hackerone-3782701",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3782701",
        "sourceUrl": "https://hackerone.com/reports/3782701",
        "title": "Unauthenticated RCE in Taskcluster web-server via GraphQL filter argument (sift $where)",
        "program": "Mozilla",
        "programUrl": "https://hackerone.com/mozilla",
        "reporter": "griffinf",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-08-05",
        "submittedAt": "2026-06-04",
        "weakness": "Code Injection",
        "vulnerabilityClass": "injection",
        "bounty": {
          "value": 12000,
          "currency": "USD"
        },
        "summary": "A vulnerability was discovered in the Taskcluster web-server that allowed unauthenticated remote code execution through the GraphQL filter argument. The issue was caused by the use of the 'sift' library, which compiled the filter's '$where' string into a function using 'new Function' and executed it. This allowed an attacker to run arbitrary JavaScript in the context of the Node.js process, resulting in the exposure of sensitive information such as database credentials, deployment access tokens, and encryption keys.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3827674",
      "url": "https://vulns.co/api/v1/reports/hackerone-3827674/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3827674",
      "record": {
        "id": "hackerone-3827674",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3827674",
        "sourceUrl": "https://hackerone.com/reports/3827674",
        "title": "Authentication Bypass via XML Signature Wrapping in SAML SSO",
        "program": "Rocket.Chat",
        "programUrl": "https://hackerone.com/rocket_chat",
        "reporter": "0jayden",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-07-27",
        "submittedAt": "2026-06-26",
        "weakness": "Improper Authentication - Generic",
        "vulnerabilityClass": "identity",
        "cves": [
          "CVE-2026-58066"
        ],
        "summary": "The SAML SSO implementation in Rocket.Chat verified XML signatures but did not bind the validated signature to the `samlp:Response` or `saml:Assertion`. As a result, an attacker could submit a wrapped document carrying forged identity attributes alongside a valid signature made by the trusted IdP certificate, and gain unauthorized access to the system.",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-90673f82-9208-40ac-95fe-72ca160abd28",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-90673f82-9208-40ac-95fe-72ca160abd28/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-90673f82-9208-40ac-95fe-72ca160abd28",
      "record": {
        "id": "bugcrowd-90673f82-9208-40ac-95fe-72ca160abd28",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "90673f82-9208-40ac-95fe-72ca160abd28",
        "sourceUrl": "https://bugcrowd.com/disclosures/4b4a2cd5-2fee-4407-b09f-74c14a8257df/blind-sql-injection-in-search-functionality-leads-to-full-database-extraction",
        "title": "Blind SQL Injection in Search Functionality Leads to Full Database Extraction",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "molany",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-07-22",
        "submittedAt": "2026-06-28",
        "target": "https://nasa.gov",
        "vulnerabilityClass": "injection",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-331df4a0-aecd-47d5-972b-5a35e7568340",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-331df4a0-aecd-47d5-972b-5a35e7568340/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-331df4a0-aecd-47d5-972b-5a35e7568340",
      "record": {
        "id": "bugcrowd-331df4a0-aecd-47d5-972b-5a35e7568340",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "331df4a0-aecd-47d5-972b-5a35e7568340",
        "sourceUrl": "https://bugcrowd.com/disclosures/c6b4ca39-0432-4180-995d-93ddec8ff614/critical-authentication-bypass-via-path-normalization-double-slash-on-live-nasa-modaps-okapi-production-instance",
        "title": "Critical Authentication Bypass via Path Normalization (Double Slash) on Live NASA MODAPS OKAPI Production Instance",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "marcelojr",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-07-22",
        "submittedAt": "2026-07-03",
        "target": "https://nasa.gov",
        "vulnerabilityClass": "identity",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-41d2d9d1-056d-453b-b8cb-89b1f53c72f4",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-41d2d9d1-056d-453b-b8cb-89b1f53c72f4/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-41d2d9d1-056d-453b-b8cb-89b1f53c72f4",
      "record": {
        "id": "bugcrowd-41d2d9d1-056d-453b-b8cb-89b1f53c72f4",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "41d2d9d1-056d-453b-b8cb-89b1f53c72f4",
        "sourceUrl": "https://bugcrowd.com/disclosures/e0f7b8d5-b90a-4a50-b531-2da37e802c84/unauthenticated-error-based-sql-injection-in-heasarc-w3browse-w3hdprods-pl",
        "title": "Unauthenticated Error-Based SQL Injection in HEASARC W3Browse w3hdprods.pl",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "Anon0x0",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-07-13",
        "submittedAt": "2026-07-04",
        "target": "https://nasa.gov",
        "vulnerabilityClass": "injection",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-f77bc17e-c0f3-4622-a113-a7555f28b52f",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-f77bc17e-c0f3-4622-a113-a7555f28b52f/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-f77bc17e-c0f3-4622-a113-a7555f28b52f",
      "record": {
        "id": "bugcrowd-f77bc17e-c0f3-4622-a113-a7555f28b52f",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "f77bc17e-c0f3-4622-a113-a7555f28b52f",
        "sourceUrl": "https://bugcrowd.com/disclosures/10cb4a9f-9173-4aca-9429-1b994a6233e6/command-injection-via-unsanitized-filename-in-nasa-ocssw-matchup-tools",
        "title": "Command Injection via Unsanitized Filename in NASA OCSSW Matchup Tools",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "KaranKurani",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-07-02",
        "submittedAt": "2026-05-31",
        "vulnerabilityClass": "injection",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-148c2b04-1afd-422c-a775-1010d0466ebb",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-148c2b04-1afd-422c-a775-1010d0466ebb/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-148c2b04-1afd-422c-a775-1010d0466ebb",
      "record": {
        "id": "bugcrowd-148c2b04-1afd-422c-a775-1010d0466ebb",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "148c2b04-1afd-422c-a775-1010d0466ebb",
        "sourceUrl": "https://bugcrowd.com/disclosures/72e039d9-7e6c-4548-b1c3-4e278e573c6e/unauthenticated-restricted-file-read-and-out-of-tree-file-disclosure-via-getvectorfile-php",
        "title": "Unauthenticated Restricted File Read and Out-of-Tree File Disclosure via GetVectorFile.php",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "freebird",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-06-23",
        "submittedAt": "2026-05-27",
        "target": "https://nasa.gov",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3723458",
      "url": "https://vulns.co/api/v1/reports/hackerone-3723458/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3723458",
      "record": {
        "id": "hackerone-3723458",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3723458",
        "sourceUrl": "https://hackerone.com/reports/3723458",
        "title": "1-Click Account Takeover via Open Redirect through Regex Bypass in Domain Validation",
        "program": "Khan Academy",
        "programUrl": "https://hackerone.com/khanacademy",
        "reporter": "farr",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-06-20",
        "submittedAt": "2026-05-09",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "A vulnerability was discovered in the Khan Academy platform that allowed an attacker to achieve full account takeover of any user. The vulnerability was caused by an unescaped dot flaw in the regular expression used to validate redirect URLs. This allowed the attacker to register a malicious domain that passed the validation check, causing the victim's authentication token to be sent to the attacker's server. The attacker could then use this token to gain full access to the victim's account. The issue was addressed by escaping the dots in the regular expression.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3804525",
      "url": "https://vulns.co/api/v1/reports/hackerone-3804525/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3804525",
      "record": {
        "id": "hackerone-3804525",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3804525",
        "sourceUrl": "https://hackerone.com/reports/3804525",
        "title": "Vulnerability Report: Buffer Overflow in Path Sanitization",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "newstuff321",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-06-16",
        "submittedAt": "2026-06-15",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3687142",
      "url": "https://vulns.co/api/v1/reports/hackerone-3687142/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3687142",
      "record": {
        "id": "hackerone-3687142",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3687142",
        "sourceUrl": "https://hackerone.com/reports/3687142",
        "title": "Unauthenticated reading of every file via livechat auth and predicting MongoDB ObjectId()",
        "program": "Rocket.Chat",
        "programUrl": "https://hackerone.com/rocket_chat",
        "reporter": "aikido_security",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-06-15",
        "submittedAt": "2026-04-21",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "cves": [
          "CVE-2026-48616"
        ],
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-ed7b7ca0-5464-4654-aaf8-93dc2fcbeca1",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-ed7b7ca0-5464-4654-aaf8-93dc2fcbeca1/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-ed7b7ca0-5464-4654-aaf8-93dc2fcbeca1",
      "record": {
        "id": "bugcrowd-ed7b7ca0-5464-4654-aaf8-93dc2fcbeca1",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "ed7b7ca0-5464-4654-aaf8-93dc2fcbeca1",
        "sourceUrl": "https://bugcrowd.com/disclosures/d854e13a-f8fb-47a1-bd86-93538c60f1c6/blind-boolean-based-sql-injection-in-label-parameter-allows-unauthenticated-database-enumeration",
        "title": "Blind Boolean-Based SQL Injection in label Parameter Allows Unauthenticated Database Enumeration",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "martindios",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-06-12",
        "submittedAt": "2026-04-19",
        "target": "https://nasa.gov",
        "vulnerabilityClass": "injection",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:research-brutecat-google-ai-500k",
      "url": "https://vulns.co/api/v1/reports/research-brutecat-google-ai-500k/",
      "webUrl": "https://vulns.co/reports/#report-research-brutecat-google-ai-500k",
      "record": {
        "id": "research-brutecat-google-ai-500k",
        "source": "researcher",
        "sourceLabel": "Brutecat",
        "sourceType": "program-research",
        "sourceUrl": "https://brutecat.com/articles/hacking-google-with-ai/",
        "title": "Hacking Google with A.I. for $500,000",
        "program": "Google VRP",
        "reporter": "Brutecat",
        "severityLabel": "Program research",
        "severitySystem": "Publication type, not severity",
        "severityBasis": "not-severity",
        "disclosedAt": "2026-06-11",
        "vulnerabilityClass": "access-control",
        "publishedOutcome": "$500,000 in bounties, as stated by the author.",
        "hunterAngle": "Treat machine-readable API descriptions, schema recovery, and reproducible confirmation as separate parts of a human-supervised testing pipeline.",
        "reviewStatus": "canonical-source-reviewed"
      }
    },
    {
      "id": "report:hackerone-3619288",
      "url": "https://vulns.co/api/v1/reports/hackerone-3619288/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3619288",
      "record": {
        "id": "hackerone-3619288",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3619288",
        "sourceUrl": "https://hackerone.com/reports/3619288",
        "title": "RCE + PAT Exfiltration via pull_request_target in privacy-configuration/auto-respond-pr.yml - Direct Supply Chain to All DDG Browsers",
        "program": "DuckDuckGo",
        "programUrl": "https://hackerone.com/duckduckgo",
        "reporter": "6r1ff1n",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-06-11",
        "submittedAt": "2026-03-21",
        "vulnerabilityClass": "code-execution",
        "summary": "A vulnerability was discovered in the \"auto-respond-pr.yml\" GitHub Actions workflow of the \"privacy-configuration\" repository. The workflow used the \"pull_request_target\" trigger, which checked out the fork's repository as both the \"base\" and \"PR\" branches. This allowed an attacker to control the code executed by the workflow, leading to arbitrary code execution and the exposure of the \"PRIVACY_CONFIG_PAT\" secret. The exposed token was likely used for PR auto-approval, enabling the attacker to approve their own PRs and access private repository contents. The vulnerability also resulted in the unconditional exposure of additional secrets, such as \"ASANA_ACCESS_TOKEN\" and \"GH_RO_PAT\", when a fork PR was closed.",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3619287",
      "url": "https://vulns.co/api/v1/reports/hackerone-3619287/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3619287",
      "record": {
        "id": "hackerone-3619287",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3619287",
        "sourceUrl": "https://hackerone.com/reports/3619287",
        "title": "RCE + Supply Chain Attack via pull_request_target in content-scope-scripts/semver-label.yml - Affects All DuckDuckGo Browsers",
        "program": "DuckDuckGo",
        "programUrl": "https://hackerone.com/duckduckgo",
        "reporter": "6r1ff1n",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-06-11",
        "submittedAt": "2026-03-21",
        "vulnerabilityClass": "code-execution",
        "summary": "A vulnerability was discovered in the DuckDuckGo content-scope-scripts repository's GitHub Actions workflow. The workflow used the pull_request_target trigger without access controls, allowing untrusted code from fork pull requests to be checked out and executed. This could have led to remote code execution and the potential exfiltration of sensitive information, such as API keys, on the runner. The vulnerability also could have been exploited to manipulate the automated release pipeline, potentially compromising all DuckDuckGo browsers and extensions across multiple platforms.",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-9c1100df-f7eb-4dc5-adea-def858ddb3cb",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-9c1100df-f7eb-4dc5-adea-def858ddb3cb/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-9c1100df-f7eb-4dc5-adea-def858ddb3cb",
      "record": {
        "id": "bugcrowd-9c1100df-f7eb-4dc5-adea-def858ddb3cb",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "9c1100df-f7eb-4dc5-adea-def858ddb3cb",
        "sourceUrl": "https://bugcrowd.com/disclosures/1614d1e0-56a7-4fab-bfc9-c6e1ca37e3ee/path-traversal-in-ait-core-bsc-logger-via-unauthenticated-post-request",
        "title": "Path Traversal in AIT-Core BSC Logger via Unauthenticated POST Request",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "Excal1bur",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-06-08",
        "submittedAt": "2026-04-20",
        "vulnerabilityClass": "file-boundary",
        "hunterAngle": "Trace filename, path, content type, storage, and retrieval as separate controls. Use inert files and confirm the smallest boundary violation before testing execution paths.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-86b58e64-c805-4bf8-8a17-f7f48e7e0406",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-86b58e64-c805-4bf8-8a17-f7f48e7e0406/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-86b58e64-c805-4bf8-8a17-f7f48e7e0406",
      "record": {
        "id": "bugcrowd-86b58e64-c805-4bf8-8a17-f7f48e7e0406",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "86b58e64-c805-4bf8-8a17-f7f48e7e0406",
        "sourceUrl": "https://bugcrowd.com/disclosures/d9b460c2-f9b1-4f8d-a0ec-3236f702dacf/remote-code-execution-rce-via-insecure-deserialization-in-nasa-gsfc-hplc-precision-analysis",
        "title": "Remote Code Execution (RCE) via Insecure Deserialization in NASA GSFC HPLC Precision Analysis",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "kernely",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-05-29",
        "submittedAt": "2026-04-03",
        "vulnerabilityClass": "code-execution",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:research-brutecat-stubzero-google-cloud-rce",
      "url": "https://vulns.co/api/v1/reports/research-brutecat-stubzero-google-cloud-rce/",
      "webUrl": "https://vulns.co/reports/#report-research-brutecat-stubzero-google-cloud-rce",
      "record": {
        "id": "research-brutecat-stubzero-google-cloud-rce",
        "source": "researcher",
        "sourceLabel": "Brutecat",
        "sourceType": "program-disclosure",
        "sourceUrl": "https://brutecat.com/articles/google-cloud-rce/",
        "title": "StubZero: $148,337 RCE in Google Cloud Production",
        "program": "Google Cloud production, CVE-2026-2031",
        "reporter": "Arvin Shivram",
        "severityLabel": "Program disclosure",
        "severitySystem": "Publication type, not severity",
        "severityBasis": "not-severity",
        "disclosedAt": "2026-05-22",
        "vulnerabilityClass": "code-execution",
        "cves": [
          "CVE-2026-2031"
        ],
        "publishedOutcome": "The author states P0/S0 for the initial report and a $148,337 bounty.",
        "hunterAngle": "Map exposed schemas, workflows, and internal errors as possible authorization boundaries, then validate only the smallest safe next step.",
        "reviewStatus": "canonical-source-reviewed"
      }
    },
    {
      "id": "report:bugcrowd-74b19e74-56cb-465b-bc7b-fffa6315738d",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-74b19e74-56cb-465b-bc7b-fffa6315738d/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-74b19e74-56cb-465b-bc7b-fffa6315738d",
      "record": {
        "id": "bugcrowd-74b19e74-56cb-465b-bc7b-fffa6315738d",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "74b19e74-56cb-465b-bc7b-fffa6315738d",
        "sourceUrl": "https://bugcrowd.com/disclosures/479095d0-e0f9-4b8d-bd64-feda95bb6b17/authenticated-idor-in-dirs-users-api-allows-access-to-other-users-profiles-and-pii-production",
        "title": "Authenticated IDOR in DIRS Users API Allows Access to Other Users’ Profiles and PII (Production)",
        "program": "Federal Communications Commission: Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/fcc-vdp",
        "reporter": "c3L0Mu1d3R",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-05-08",
        "submittedAt": "2026-01-16",
        "target": "*.fcc.gov",
        "vulnerabilityClass": "access-control",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-52b757fb-ec7d-4db8-8ee5-3f2f36a3ba55",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-52b757fb-ec7d-4db8-8ee5-3f2f36a3ba55/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-52b757fb-ec7d-4db8-8ee5-3f2f36a3ba55",
      "record": {
        "id": "bugcrowd-52b757fb-ec7d-4db8-8ee5-3f2f36a3ba55",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "52b757fb-ec7d-4db8-8ee5-3f2f36a3ba55",
        "sourceUrl": "https://bugcrowd.com/disclosures/4f63c6af-68cf-4d58-a1c9-911fb8a202ad/authenticated-bfla-in-dirs-critical-need-of-help-api-allows-unauthorized-access-to-all-submitted-requests-and-pii",
        "title": "Authenticated BFLA in DIRS “Critical Need of Help” API Allows Unauthorized Access to All Submitted Requests and PII",
        "program": "Federal Communications Commission: Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/fcc-vdp",
        "reporter": "c3L0Mu1d3R",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-05-08",
        "submittedAt": "2026-01-16",
        "target": "*.fcc.gov",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3307874",
      "url": "https://vulns.co/api/v1/reports/hackerone-3307874/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3307874",
      "record": {
        "id": "hackerone-3307874",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3307874",
        "sourceUrl": "https://hackerone.com/reports/3307874",
        "title": "Critical Deadlock Vulnerability in Monero RPC Leading to Complete Node Paralysis",
        "program": "Monero",
        "programUrl": "https://hackerone.com/monero",
        "reporter": "rorkh",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-05-06",
        "submittedAt": "2025-08-21",
        "weakness": "Uncontrolled Resource Consumption",
        "vulnerabilityClass": "code-execution",
        "summary": "A deadlock vulnerability was discovered in the Monero JSON-RPC interface that allowed a remote, unauthenticated attacker to completely paralyze any Monero node with a single HTTP request containing specific batch methods, leading to permanent denial of service. The vulnerability affected all releases of Monero up to version 0.18.4.2 and likely previous versions, across all operating systems. The vulnerability was rated as critical, with a CVSS 3.0 score of 10.0.",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3712343",
      "url": "https://vulns.co/api/v1/reports/hackerone-3712343/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3712343",
      "record": {
        "id": "hackerone-3712343",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3712343",
        "sourceUrl": "https://hackerone.com/reports/3712343",
        "title": "MQTT CONNACK Packet Type Bypass leads to RCE via Malicious Broker",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "orelbn7",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-05-05",
        "submittedAt": "2026-05-04",
        "weakness": "ASI05: Unexpected Code Execution (RCE)",
        "vulnerabilityClass": "code-execution",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3564655",
      "url": "https://vulns.co/api/v1/reports/hackerone-3564655/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3564655",
      "record": {
        "id": "hackerone-3564655",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3564655",
        "sourceUrl": "https://hackerone.com/reports/3564655",
        "title": "Complete authentication bypass to admin permissions",
        "program": "Rocket.Chat",
        "programUrl": "https://hackerone.com/rocket_chat",
        "reporter": "npc",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-04-22",
        "submittedAt": "2026-02-20",
        "weakness": "SQL Injection",
        "vulnerabilityClass": "injection",
        "cves": [
          "CVE-2026-29198"
        ],
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3669305",
      "url": "https://vulns.co/api/v1/reports/hackerone-3669305/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3669305",
      "record": {
        "id": "hackerone-3669305",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3669305",
        "sourceUrl": "https://hackerone.com/reports/3669305",
        "title": "Argument Injection via curl Short-Flag Grouping",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "midoussa7",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-04-13",
        "submittedAt": "2026-04-13",
        "weakness": "Command Injection - Generic",
        "vulnerabilityClass": "injection",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3648199",
      "url": "https://vulns.co/api/v1/reports/hackerone-3648199/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3648199",
      "record": {
        "id": "hackerone-3648199",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3648199",
        "sourceUrl": "https://hackerone.com/reports/3648199",
        "title": "Internal application wrapper or script using curl",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "rougerseven7",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-04-03",
        "submittedAt": "2026-04-03",
        "weakness": "Code Injection",
        "vulnerabilityClass": "injection",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-58e5715c-de97-4b79-b365-2116552d98c6",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-58e5715c-de97-4b79-b365-2116552d98c6/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-58e5715c-de97-4b79-b365-2116552d98c6",
      "record": {
        "id": "bugcrowd-58e5715c-de97-4b79-b365-2116552d98c6",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "58e5715c-de97-4b79-b365-2116552d98c6",
        "sourceUrl": "https://bugcrowd.com/disclosures/b14596f7-3e6a-472b-9c0f-83996e53969a/critical-admin-access-vulnerability-on-nasa-s-satcorps-smce-nasa-gov-subdomain",
        "title": "Critical Admin Access Vulnerability on NASA’s *.satcorps.smce.nasa.gov Subdomain",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "aashutoshdevkota",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-03-24",
        "submittedAt": "2024-06-18",
        "target": "https://nasa.gov",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-0dae15fd-d6bd-4831-9f4d-2a1dc5920f52",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-0dae15fd-d6bd-4831-9f4d-2a1dc5920f52/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-0dae15fd-d6bd-4831-9f4d-2a1dc5920f52",
      "record": {
        "id": "bugcrowd-0dae15fd-d6bd-4831-9f4d-2a1dc5920f52",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "0dae15fd-d6bd-4831-9f4d-2a1dc5920f52",
        "sourceUrl": "https://bugcrowd.com/disclosures/ef50e1dd-1cc5-4c85-908d-cdc384a89bd3/internal-solr-query-injection-enabling-local-file-inclusion-and-potential-ssrf-on-trek-nasa-gov",
        "title": "Internal Solr Query Injection enabling Local FIle Inclusion and Potential SSRF on trek.nasa.gov",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "YeJunWon",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-03-23",
        "submittedAt": "2026-03-02",
        "target": "https://nasa.gov",
        "vulnerabilityClass": "injection",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-31e5470d-d009-4736-8464-198880f58833",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-31e5470d-d009-4736-8464-198880f58833/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-31e5470d-d009-4736-8464-198880f58833",
      "record": {
        "id": "bugcrowd-31e5470d-d009-4736-8464-198880f58833",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "31e5470d-d009-4736-8464-198880f58833",
        "sourceUrl": "https://bugcrowd.com/disclosures/948921ed-6603-4d2b-9022-f25f6552138f/unauthenticated-remote-code-execution-rce-via-unsafe-clojure-deserialization-on-cmr-earthdata-nasa-gov",
        "title": "Unauthenticated Remote Code Execution (RCE) via Unsafe Clojure Deserialization on cmr.earthdata.nasa.gov",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "obaskly",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-03-20",
        "submittedAt": "2026-02-23",
        "target": "https://nasa.gov",
        "vulnerabilityClass": "code-execution",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-4a91cca2-27d5-4a67-9bec-e0972216a50b",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-4a91cca2-27d5-4a67-9bec-e0972216a50b/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-4a91cca2-27d5-4a67-9bec-e0972216a50b",
      "record": {
        "id": "bugcrowd-4a91cca2-27d5-4a67-9bec-e0972216a50b",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "4a91cca2-27d5-4a67-9bec-e0972216a50b",
        "sourceUrl": "https://bugcrowd.com/disclosures/9d2c7b28-7ff7-439c-9149-f74a883815e3/xml-external-entity-xxe-injection-via-regex-bypass-in-cmr-aql-parsing-enables-ssrf-service-enumeration-and-blind-file-reads",
        "title": "XML External Entity (XXE) Injection via Regex Bypass in CMR AQL Parsing Enables SSRF, Service Enumeration, and Blind File Reads",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "dewankpant",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-03-17",
        "submittedAt": "2026-02-01",
        "target": "https://nasa.gov",
        "vulnerabilityClass": "injection",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3578842",
      "url": "https://vulns.co/api/v1/reports/hackerone-3578842/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3578842",
      "record": {
        "id": "hackerone-3578842",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3578842",
        "sourceUrl": "https://hackerone.com/reports/3578842",
        "title": "SQL Injection vulnerability found on ibm.com endpoint",
        "program": "IBM",
        "programUrl": "https://hackerone.com/ibm",
        "reporter": "uzki",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-03-12",
        "submittedAt": "2026-02-28",
        "weakness": "SQL Injection",
        "vulnerabilityClass": "injection",
        "summary": "A SQL injection vulnerability was found on an ibm.com endpoint. The vulnerability was reported to IBM, analyzed, and remediated.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-1c831d19-cc86-4116-9761-0d8033782324",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-1c831d19-cc86-4116-9761-0d8033782324/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-1c831d19-cc86-4116-9761-0d8033782324",
      "record": {
        "id": "bugcrowd-1c831d19-cc86-4116-9761-0d8033782324",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "1c831d19-cc86-4116-9761-0d8033782324",
        "sourceUrl": "https://bugcrowd.com/disclosures/abfa03c7-9c7d-46f7-b255-9766199dac4a/saml-authentication-bypass-leading-to-unauthenticated-admin-takeover-on-scijinks-gov-nesdis-noaa-gov",
        "title": "SAML Authentication Bypass Leading To Unauthenticated Admin Takeover on scijinks.gov / nesdis.noaa.gov",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "meeranh",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-03-11",
        "submittedAt": "2026-03-01",
        "target": "https://scijinks.gov/",
        "vulnerabilityClass": "identity",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-8ebdf708-117f-4777-adc5-24aaf243f20b",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-8ebdf708-117f-4777-adc5-24aaf243f20b/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-8ebdf708-117f-4777-adc5-24aaf243f20b",
      "record": {
        "id": "bugcrowd-8ebdf708-117f-4777-adc5-24aaf243f20b",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "8ebdf708-117f-4777-adc5-24aaf243f20b",
        "sourceUrl": "https://bugcrowd.com/disclosures/6cea28c5-b3a9-45a8-8617-826ba0649279/default-credentials-for-teamwork-cloud",
        "title": "Default credentials for Teamwork Cloud",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "jpablo",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-03-09",
        "submittedAt": "2025-09-29",
        "target": "https://nasa.gov",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-deb4818a-2728-45bc-87ae-9911ecffc6da",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-deb4818a-2728-45bc-87ae-9911ecffc6da/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-deb4818a-2728-45bc-87ae-9911ecffc6da",
      "record": {
        "id": "bugcrowd-deb4818a-2728-45bc-87ae-9911ecffc6da",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "deb4818a-2728-45bc-87ae-9911ecffc6da",
        "sourceUrl": "https://bugcrowd.com/disclosures/7c919b14-e9df-47a1-bae0-206f77c1379c/pii-exposure-in-nasa-nssc-internal-procedure-pdf",
        "title": "PII Exposure in NASA NSSC Internal Procedure PDF",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "Daniyal_khan",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-03-05",
        "submittedAt": "2026-01-20",
        "target": "https://nasa.gov",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3293803",
      "url": "https://vulns.co/api/v1/reports/hackerone-3293803/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3293803",
      "record": {
        "id": "hackerone-3293803",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3293803",
        "sourceUrl": "https://hackerone.com/reports/3293803",
        "title": "SQLi At `███████` via `theme_name`",
        "program": "Mars",
        "programUrl": "https://hackerone.com/mars",
        "reporter": "4ksh3ye",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-02-24",
        "submittedAt": "2025-08-10",
        "weakness": "SQL Injection",
        "vulnerabilityClass": "injection",
        "summary": "A SQL injection vulnerability was discovered in a web application's theme selection endpoint through the \"theme_name\" parameter. Using SQLMap, the vulnerability was demonstrated to be exploitable through both error-based and time-based blind injection attacks against a MySQL database (version 5.1 or newer). The exploitation successfully enumerated several databases, including sensitive repositories for authentication, payment, and security data. The development team implemented fixes using parameterized queries and input validation, and post-remediation testing confirmed the vulnerability was fully resolved.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3277276",
      "url": "https://vulns.co/api/v1/reports/hackerone-3277276/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3277276",
      "record": {
        "id": "hackerone-3277276",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3277276",
        "sourceUrl": "https://hackerone.com/reports/3277276",
        "title": "SQLi at █████ parameter",
        "program": "Mars",
        "programUrl": "https://hackerone.com/mars",
        "reporter": "scriptsavvy",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-02-24",
        "submittedAt": "2025-07-29",
        "weakness": "SQL Injection",
        "vulnerabilityClass": "injection",
        "summary": "A SQL injection vulnerability was discovered in an items endpoint that accepted unauthenticated POST requests without CSRF validation. The vulnerability allowed execution of arbitrary SQL commands and extraction of database metadata. Additional security issues included stored XSS through the description parameter and lack of authentication controls. The vulnerability was promptly remediated by the security team.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2200329",
      "url": "https://vulns.co/api/v1/reports/hackerone-2200329/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2200329",
      "record": {
        "id": "hackerone-2200329",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2200329",
        "sourceUrl": "https://hackerone.com/reports/2200329",
        "title": "CVE-█████-35813 in █████",
        "program": "Mars",
        "programUrl": "https://hackerone.com/mars",
        "reporter": "0xr2r",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-02-24",
        "submittedAt": "2023-10-10",
        "weakness": "Relative Path Traversal",
        "vulnerabilityClass": "file-boundary",
        "cves": [
          "CVE-2023-35813"
        ],
        "summary": "A critical remote code execution vulnerability (CVE-█████-35813) affecting multiple Sitecore products through version 10.3 was discovered. The vulnerability was exploited through the sitecore_xaml.ashx endpoint using ASP.NET TemplateParser injection, allowing attackers to execute arbitrary code. The organization successfully applied the Sitecore security patch, and subsequent retesting confirmed the vulnerability was fully remediated.",
        "hunterAngle": "Trace filename, path, content type, storage, and retrieval as separate controls. Use inert files and confirm the smallest boundary violation before testing execution paths.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-32500e6a-949b-4488-8225-ed84758fff92",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-32500e6a-949b-4488-8225-ed84758fff92/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-32500e6a-949b-4488-8225-ed84758fff92",
      "record": {
        "id": "bugcrowd-32500e6a-949b-4488-8225-ed84758fff92",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "32500e6a-949b-4488-8225-ed84758fff92",
        "sourceUrl": "https://bugcrowd.com/disclosures/482e1b73-d645-4511-936e-a051da3fa66d/deleted-sku-causes-crash-in-user-manage-subscriptions-page",
        "title": "Deleted SKU Causes Crash in User Manage Subscriptions page.",
        "reporter": "NeverCookFirst",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2026-02-02",
        "submittedAt": "2025-07-05",
        "target": "Platform Access - Web App",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3459285",
      "url": "https://vulns.co/api/v1/reports/hackerone-3459285/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3459285",
      "record": {
        "id": "hackerone-3459285",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3459285",
        "sourceUrl": "https://hackerone.com/reports/3459285",
        "title": "[Critical] Unauthorized Cross-Tenant Data Access in Stripo AI Hub Campaign via Deleted Project.",
        "program": "Stripo Inc",
        "programUrl": "https://hackerone.com/stripo",
        "reporter": "srcode",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-01-20",
        "submittedAt": "2025-12-09",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "An unauthorized cross-tenant data access vulnerability was discovered in the Stripo AI Hub Campaign. The vulnerability allowed access to data from a deleted project. The issue was resolved.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3516186",
      "url": "https://vulns.co/api/v1/reports/hackerone-3516186/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3516186",
      "record": {
        "id": "hackerone-3516186",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3516186",
        "sourceUrl": "https://hackerone.com/reports/3516186",
        "title": "Cookie Max-Age Integer Overflow Vulnerability",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "bhaskar_ram",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-01-19",
        "submittedAt": "2026-01-19",
        "weakness": "Integer Overflow",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3509437",
      "url": "https://vulns.co/api/v1/reports/hackerone-3509437/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3509437",
      "record": {
        "id": "hackerone-3509437",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3509437",
        "sourceUrl": "https://hackerone.com/reports/3509437",
        "title": "Directory listing vulnerability is disclosing names and emails, widespread (thousands of records, publicly accessible without auth)",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "sawhack100",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-01-14",
        "submittedAt": "2026-01-13",
        "weakness": "Information Exposure Through Directory Listing",
        "vulnerabilityClass": "data-exposure",
        "hunterAngle": "Identify the intended audience and the narrowest unauthorized observer. Use controlled records, distinguish metadata from secret material, and quantify the repeatable exposure boundary.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3414079",
      "url": "https://vulns.co/api/v1/reports/hackerone-3414079/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3414079",
      "record": {
        "id": "hackerone-3414079",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3414079",
        "sourceUrl": "https://hackerone.com/reports/3414079",
        "title": "DNN - Unrestricted Arbitrary File Upload #████████",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "0xr2r",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-01-12",
        "submittedAt": "2025-11-06",
        "weakness": "File Content Injection",
        "vulnerabilityClass": "injection",
        "cves": [
          "CVE-2025-64095"
        ],
        "summary": "A vulnerability was discovered in versions of DNN (formerly DotNetNuke) prior to 10.1.1. The vulnerability was caused by the default HTML editor provider allowing unauthenticated file uploads and overwriting of existing files. This could have led to website defacement and cross-site scripting attacks.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3078508",
      "url": "https://vulns.co/api/v1/reports/hackerone-3078508/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3078508",
      "record": {
        "id": "hackerone-3078508",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3078508",
        "sourceUrl": "https://hackerone.com/reports/3078508",
        "title": "[Critical Data Breach] Exposure of PII Data Leak via API Response",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "rocky1696",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-01-12",
        "submittedAt": "2025-04-04",
        "weakness": "Cleartext Storage of Sensitive Information",
        "vulnerabilityClass": "critical-path",
        "summary": "A critical information disclosure vulnerability was discovered, exposing sensitive user data via an API response. The leaked data included personal information such as full name, email, and phone number.",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2968391",
      "url": "https://vulns.co/api/v1/reports/hackerone-2968391/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2968391",
      "record": {
        "id": "hackerone-2968391",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2968391",
        "sourceUrl": "https://hackerone.com/reports/2968391",
        "title": "Air Force candidate PII + recruitment chat logs accessible via BAC/IDOR on █████████ (very large/significant exposure)",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "oxylis",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-01-12",
        "submittedAt": "2025-01-31",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "A vulnerability was discovered in a Department of Defense-owned Salesforce asset that allowed unauthorized access to sensitive personal information of Air Force candidates. The vulnerability stemmed from a misconfiguration in the Document object, which permitted an attacker to retrieve a large number of records containing private chat logs, full names, addresses, phone numbers, email addresses, medical data, drug use history, criminal history, and academic data. The impact of this vulnerability was considered high due to the significant exposure of personally identifiable information.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2954320",
      "url": "https://vulns.co/api/v1/reports/hackerone-2954320/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2954320",
      "record": {
        "id": "hackerone-2954320",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2954320",
        "sourceUrl": "https://hackerone.com/reports/2954320",
        "title": "ASBS viewing other soldiers PII/Board/Board Voters/ETC",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "badlifeguard",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-01-12",
        "submittedAt": "2025-01-22",
        "weakness": "Information Disclosure",
        "vulnerabilityClass": "data-exposure",
        "summary": "The vulnerability allowed an authenticated user to run GraphQL queries that returned sensitive information on other users, such as their personally identifiable information, board information, and clearance details. The vulnerability was present in version 1.09.00.0 of the affected system and partially impacted various components within the Department of Defense.",
        "hunterAngle": "Identify the intended audience and the narrowest unauthorized observer. Use controlled records, distinguish metadata from secret material, and quantify the repeatable exposure boundary.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2857082",
      "url": "https://vulns.co/api/v1/reports/hackerone-2857082/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2857082",
      "record": {
        "id": "hackerone-2857082",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2857082",
        "sourceUrl": "https://hackerone.com/reports/2857082",
        "title": "Exposed Extremely Sensitive Information in Public ZIP File",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "aldenpartridge",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-01-12",
        "submittedAt": "2024-11-20",
        "weakness": "Insecure Storage of Sensitive Information",
        "vulnerabilityClass": "critical-path",
        "summary": "A publicly accessible ZIP file containing sensitive information, including SMTP credentials, database connection details, and AWS secret keys, was discovered. The sensitive data was exposed due to the lack of proper access controls and encryption. The exposed credentials could have been misused for unauthorized access and actions.",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2468496",
      "url": "https://vulns.co/api/v1/reports/hackerone-2468496/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2468496",
      "record": {
        "id": "hackerone-2468496",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2468496",
        "sourceUrl": "https://hackerone.com/reports/2468496",
        "title": "GlobalProtect - OS Command Injection #█████████",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "0xr2r",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-01-12",
        "submittedAt": "2024-04-18",
        "weakness": "OS Command Injection",
        "vulnerabilityClass": "injection",
        "cves": [
          "CVE-2024-3400"
        ],
        "summary": "A command injection vulnerability was discovered in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations. This vulnerability could have enabled an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access were not impacted by this vulnerability.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3487952",
      "url": "https://vulns.co/api/v1/reports/hackerone-3487952/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3487952",
      "record": {
        "id": "hackerone-3487952",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3487952",
        "sourceUrl": "https://hackerone.com/reports/3487952",
        "title": "State Isolation Failure in Multiplexed Connections (Shared Auth Context)",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "raulvdv",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-01-08",
        "submittedAt": "2026-01-05",
        "weakness": "Exposure of Data Element to Wrong Session",
        "vulnerabilityClass": "identity",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2830573",
      "url": "https://vulns.co/api/v1/reports/hackerone-2830573/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2830573",
      "record": {
        "id": "hackerone-2830573",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2830573",
        "sourceUrl": "https://hackerone.com/reports/2830573",
        "title": "SQL injection identified on IBM endpoint.",
        "program": "IBM",
        "programUrl": "https://hackerone.com/ibm",
        "reporter": "rakib0x7",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2026-01-07",
        "submittedAt": "2024-11-08",
        "weakness": "SQL Injection",
        "vulnerabilityClass": "injection",
        "summary": "SQL injection vulnerability was identified on an IBM endpoint. The issue was reported to IBM, analyzed, and remediated.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3463045",
      "url": "https://vulns.co/api/v1/reports/hackerone-3463045/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3463045",
      "record": {
        "id": "hackerone-3463045",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3463045",
        "sourceUrl": "https://hackerone.com/reports/3463045",
        "title": "Remote Code Execution identified on IBM endpoint.",
        "program": "IBM",
        "programUrl": "https://hackerone.com/ibm",
        "reporter": "dara_7979",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-12-31",
        "submittedAt": "2025-12-12",
        "vulnerabilityClass": "code-execution",
        "cves": [
          "CVE-2025-55182"
        ],
        "summary": "A remote code execution vulnerability was identified on an IBM endpoint. The issue was reported to IBM, analyzed, and remediated.",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-34c78a3a-88bd-4c56-8c1b-632bc0ea3742",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-34c78a3a-88bd-4c56-8c1b-632bc0ea3742/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-34c78a3a-88bd-4c56-8c1b-632bc0ea3742",
      "record": {
        "id": "bugcrowd-34c78a3a-88bd-4c56-8c1b-632bc0ea3742",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "34c78a3a-88bd-4c56-8c1b-632bc0ea3742",
        "sourceUrl": "https://bugcrowd.com/disclosures/e07fc7bd-9d1f-421e-978c-71c2802b2697/security-vulnerability-report-txt-version-react2shell-cve-2025-55182",
        "title": "SECURITY VULNERABILITY REPORT (TXT VERSION) React2Shell CVE-2025-55182",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "Dennisec_N00b",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2025-12-30",
        "submittedAt": "2025-12-07",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3480641",
      "url": "https://vulns.co/api/v1/reports/hackerone-3480641/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3480641",
      "record": {
        "id": "hackerone-3480641",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3480641",
        "sourceUrl": "https://hackerone.com/reports/3480641",
        "title": "Cross‑Layer State Confusion in libcurl: Credential & Key‑Material Persistence Across Redirect / Connection Reuse Boundaries",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "onevone",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-12-28",
        "submittedAt": "2025-12-28",
        "weakness": "Violation of Secure Design Principles",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3479984",
      "url": "https://vulns.co/api/v1/reports/hackerone-3479984/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3479984",
      "record": {
        "id": "hackerone-3479984",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3479984",
        "sourceUrl": "https://hackerone.com/reports/3479984",
        "title": "CRLF Injection / Protocol Smuggling in libcurl via CURLOPT_USERNAME (IMAP)",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "efrsxcv",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-12-28",
        "submittedAt": "2025-12-27",
        "weakness": "CRLF Injection",
        "vulnerabilityClass": "injection",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3479203",
      "url": "https://vulns.co/api/v1/reports/hackerone-3479203/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3479203",
      "record": {
        "id": "hackerone-3479203",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3479203",
        "sourceUrl": "https://hackerone.com/reports/3479203",
        "title": "HTTP/3 Protocol Smuggling and Header Injection via CRLF in QPACK value conversion",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "0x0000nosfu",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-12-27",
        "submittedAt": "2025-12-26",
        "weakness": "CRLF Injection",
        "vulnerabilityClass": "injection",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:research-arkark-etag-length-leak",
      "url": "https://vulns.co/api/v1/reports/research-arkark-etag-length-leak/",
      "webUrl": "https://vulns.co/reports/#report-research-arkark-etag-length-leak",
      "record": {
        "id": "research-arkark-etag-length-leak",
        "source": "researcher",
        "sourceLabel": "arkark",
        "sourceType": "technique-research",
        "sourceUrl": "https://blog.arkark.dev/2025/12/26/etag-length-leak",
        "title": "Cross-Site ETag Length Leak",
        "program": "Cross-site browser contexts",
        "reporter": "Takeshi Kaneko",
        "severityLabel": "Technique research",
        "severitySystem": "Publication type, not severity",
        "severityBasis": "not-severity",
        "disclosedAt": "2025-12-26",
        "vulnerabilityClass": "browser-client",
        "publishedOutcome": "The post presents a proof-of-concept technique, not a vendor severity.",
        "hunterAngle": "Test metadata, headers, cache state, and response-size signals separately from body-access assumptions.",
        "reviewStatus": "canonical-source-reviewed"
      }
    },
    {
      "id": "report:bugcrowd-547a2f57-37a4-446a-af5d-11e4b24204e2",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-547a2f57-37a4-446a-af5d-11e4b24204e2/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-547a2f57-37a4-446a-af5d-11e4b24204e2",
      "record": {
        "id": "bugcrowd-547a2f57-37a4-446a-af5d-11e4b24204e2",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "547a2f57-37a4-446a-af5d-11e4b24204e2",
        "sourceUrl": "https://bugcrowd.com/disclosures/41e70d21-db93-463c-a80e-4ee03942a481/cve-2025-55182-deserialization-on-vizss-czdt-smce-nasa-gov-through-via-post-parameter-0-leads-to-remote-code-execution-rce",
        "title": "[CVE-2025-55182] Deserialization on vizss.czdt.smce.nasa.gov through /* via POST parameter \"0\" leads to Remote Code Execution (RCE)",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "R4XxH4",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2025-12-23",
        "submittedAt": "2025-12-06",
        "target": "https://nasa.gov",
        "vulnerabilityClass": "code-execution",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:research-elttam-orm-filter-leak",
      "url": "https://vulns.co/api/v1/reports/research-elttam-orm-filter-leak/",
      "webUrl": "https://vulns.co/reports/#report-research-elttam-orm-filter-leak",
      "record": {
        "id": "research-elttam-orm-filter-leak",
        "source": "researcher",
        "sourceLabel": "elttam",
        "sourceType": "research-with-disclosures",
        "sourceUrl": "https://www.elttam.com/blog/leaking-more-than-you-joined-for/",
        "title": "ORM Leaking More Than You Joined For",
        "program": "Harbor and Directus",
        "reporter": "Alex Brown",
        "severityLabel": "Research with disclosures",
        "severitySystem": "Publication type, not severity",
        "severityBasis": "not-severity",
        "disclosedAt": "2025-12-18",
        "vulnerabilityClass": "access-control",
        "cves": [
          "CVE-2025-30086",
          "CVE-2025-64748"
        ],
        "publishedOutcome": "The source publishes disclosed vulnerabilities and Semgrep rules. No program severity is inferred.",
        "hunterAngle": "Build authorization matrices around filter field and operator mapping, relationship traversal, and sensitive-field exclusion rather than only classic injection.",
        "reviewStatus": "canonical-source-reviewed"
      }
    },
    {
      "id": "report:hackerone-3458235",
      "url": "https://vulns.co/api/v1/reports/hackerone-3458235/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3458235",
      "record": {
        "id": "hackerone-3458235",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3458235",
        "sourceUrl": "https://hackerone.com/reports/3458235",
        "title": "[RCE] Remote Code Execution via React Server Components Vulnerability CVE-2025-55182",
        "program": "IBM",
        "programUrl": "https://hackerone.com/ibm",
        "reporter": "kanon4",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-12-18",
        "submittedAt": "2025-12-09",
        "weakness": "Code Injection",
        "vulnerabilityClass": "injection",
        "cves": [
          "CVE-2025-55182"
        ],
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-c965e539-8d25-473e-8879-feb612715669",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-c965e539-8d25-473e-8879-feb612715669/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-c965e539-8d25-473e-8879-feb612715669",
      "record": {
        "id": "bugcrowd-c965e539-8d25-473e-8879-feb612715669",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "c965e539-8d25-473e-8879-feb612715669",
        "sourceUrl": "https://bugcrowd.com/disclosures/8c24664f-682e-43b6-83eb-885508405ac3/xml-external-entity-injection-in-nasa-cmr-ingest-api-info-dump",
        "title": "XML External Entity Injection in NASA CMR Ingest API - info dump",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "thomasito",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2025-12-17",
        "submittedAt": "2025-10-25",
        "target": "https://nasa.gov",
        "vulnerabilityClass": "injection",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3462525",
      "url": "https://vulns.co/api/v1/reports/hackerone-3462525/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3462525",
      "record": {
        "id": "hackerone-3462525",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3462525",
        "sourceUrl": "https://hackerone.com/reports/3462525",
        "title": "Buffer Overflow in cURL Internal printf Function",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "mlgzackfly",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-12-12",
        "submittedAt": "2025-12-12",
        "weakness": "Stack Overflow",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:research-watchtowr-soapwn",
      "url": "https://vulns.co/api/v1/reports/research-watchtowr-soapwn/",
      "webUrl": "https://vulns.co/reports/#report-research-watchtowr-soapwn",
      "record": {
        "id": "research-watchtowr-soapwn",
        "source": "researcher",
        "sourceLabel": "watchTowr Labs",
        "sourceType": "research-with-disclosures",
        "sourceUrl": "https://labs.watchtowr.com/soapwn-pwning-net-framework-applications-through-http-client-proxies-and-wsdl/",
        "title": "SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL",
        "program": "Barracuda Service Center RMM, Ivanti Endpoint Manager, and named products",
        "reporter": "Piotr Bazydlo",
        "severityLabel": "Research with disclosures",
        "severitySystem": "Publication type, not severity",
        "severityBasis": "not-severity",
        "disclosedAt": "2025-12-10",
        "vulnerabilityClass": "code-execution",
        "cves": [
          "CVE-2025-34392",
          "CVE-2025-13659"
        ],
        "publishedOutcome": "The source identifies a pre-authentication Barracuda issue and patch details, without one universal severity.",
        "hunterAngle": "For authorized source-assisted work, trace attacker-controlled URL schemes through client-proxy generation and generated-code execution boundaries.",
        "reviewStatus": "canonical-source-reviewed"
      }
    },
    {
      "id": "report:hackerone-3444904",
      "url": "https://vulns.co/api/v1/reports/hackerone-3444904/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3444904",
      "record": {
        "id": "hackerone-3444904",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3444904",
        "sourceUrl": "https://hackerone.com/reports/3444904",
        "title": "Heap Buffer Overflow in TFTP",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "helspy",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-12-01",
        "submittedAt": "2025-11-29",
        "weakness": "Heap Overflow",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2932960",
      "url": "https://vulns.co/api/v1/reports/hackerone-2932960/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2932960",
      "record": {
        "id": "hackerone-2932960",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2932960",
        "sourceUrl": "https://hackerone.com/reports/2932960",
        "title": "[my.stripo.email] Blind SSRF Vulnerability in Stripo App Export via Missing Endpoints Export Email Message to Zapier",
        "program": "Stripo Inc",
        "programUrl": "https://hackerone.com/stripo",
        "reporter": "odaysec",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-12-01",
        "submittedAt": "2025-01-13",
        "weakness": "Server-Side Request Forgery (SSRF)",
        "vulnerabilityClass": "ssrf",
        "summary": "A critical Blind SSRF (Server-Side Request Forgery) vulnerability was identified in the export service of the Stripo app. The vulnerability existed in the endpoint `/exportservice/v3/exports/WEBHOOK/accounts`, where malicious input could be provided in the `webhookUrl` parameter, triggering SSRF and allowing the server to make unauthorized HTTP requests to attacker-controlled systems.",
        "hunterAngle": "Map URL parsing, redirects, DNS resolution, and egress as separate decisions. Use an owned callback and compare it with a non-routable control without probing unrelated internal services.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:bugcrowd-983f0851-ceff-4534-a5d0-b508c22ee79c",
      "url": "https://vulns.co/api/v1/reports/bugcrowd-983f0851-ceff-4534-a5d0-b508c22ee79c/",
      "webUrl": "https://vulns.co/reports/#report-bugcrowd-983f0851-ceff-4534-a5d0-b508c22ee79c",
      "record": {
        "id": "bugcrowd-983f0851-ceff-4534-a5d0-b508c22ee79c",
        "source": "bugcrowd",
        "sourceLabel": "Bugcrowd",
        "sourceId": "983f0851-ceff-4534-a5d0-b508c22ee79c",
        "sourceUrl": "https://bugcrowd.com/disclosures/68f4566e-2358-40c2-92d0-3a5e21023908/idor-that-allows-disclosing-username-email-firstname-lastname-address-phonenumbers-of-prosams-application-users",
        "title": "IDOR that allows disclosing Username,Email,FirstName,LastName,Address,PhoneNumbers of PROSAMS application users.",
        "program": "National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program",
        "programUrl": "https://bugcrowd.com/engagements/nasa-vdp",
        "reporter": "INUMA_CYBERSECURITY",
        "severityLabel": "P1",
        "severitySystem": "Bugcrowd VRT priority",
        "severityBasis": "source-native",
        "disclosedAt": "2025-11-19",
        "submittedAt": "2025-09-18",
        "target": "https://nasa.gov",
        "vulnerabilityClass": "access-control",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3417162",
      "url": "https://vulns.co/api/v1/reports/hackerone-3417162/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3417162",
      "record": {
        "id": "hackerone-3417162",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3417162",
        "sourceUrl": "https://hackerone.com/reports/3417162",
        "title": "Authentication Bypass in Subscription Management Endpoint",
        "program": "lemlist",
        "programUrl": "https://hackerone.com/lemlist",
        "reporter": "0hmz",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-11-17",
        "submittedAt": "2025-11-09",
        "weakness": "Insecure Direct Object Reference (IDOR)",
        "vulnerabilityClass": "access-control",
        "summary": "A vulnerability was identified in the subscription management functionality that allowed unauthorized access to customer billing information. The issue stemmed from insufficient authentication and authorization controls on an API endpoint. The vulnerability was classified as an Insecure Direct Object Reference (IDOR) vulnerability, where customer identifiers could be manipulated to access other users' data. The vulnerability has been promptly addressed and fixed by the development team.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3419636",
      "url": "https://vulns.co/api/v1/reports/hackerone-3419636/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3419636",
      "record": {
        "id": "hackerone-3419636",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3419636",
        "sourceUrl": "https://hackerone.com/reports/3419636",
        "title": "Authentication Token Theft via Open Redirect in Callback URL Parameter",
        "program": "lemlist",
        "programUrl": "https://hackerone.com/lemlist",
        "reporter": "sle3pyhead",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-11-14",
        "submittedAt": "2025-11-11",
        "weakness": "Insufficiently Protected Credentials",
        "vulnerabilityClass": "identity",
        "summary": "A vulnerability was identified in the email signup flow of a website that enabled authentication token theft through manipulation of the callback URL parameter. The vulnerability occurred when an attacker modified the callbackUrl parameter during the email signup process to point to an attacker-controlled domain. When a victim completed the email verification process by clicking the verification link, they were redirected to the malicious domain along with their authentication tokens. The redirection happened automatically as part of the normal signup flow. The vulnerability was caused by insufficient validation of the callback URL parameter and leveraged the trust users place in legitimate verification emails.",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3418776",
      "url": "https://vulns.co/api/v1/reports/hackerone-3418776/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3418776",
      "record": {
        "id": "hackerone-3418776",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3418776",
        "sourceUrl": "https://hackerone.com/reports/3418776",
        "title": "Silent TLS Trust Model Hijacking via `CURL_CA_BUNDLE` Environment Variable Leads to MITM",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "rootsecret3",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-11-11",
        "submittedAt": "2025-11-10",
        "weakness": "Improper Certificate Validation",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3418646",
      "url": "https://vulns.co/api/v1/reports/hackerone-3418646/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3418646",
      "record": {
        "id": "hackerone-3418646",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3418646",
        "sourceUrl": "https://hackerone.com/reports/3418646",
        "title": "Arbitrary Configuration File Inclusion: via External Control of File Name or Path",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "rootsecret3",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-11-10",
        "submittedAt": "2025-11-10",
        "weakness": "External Control of File Name or Path",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3418616",
      "url": "https://vulns.co/api/v1/reports/hackerone-3418616/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3418616",
      "record": {
        "id": "hackerone-3418616",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3418616",
        "sourceUrl": "https://hackerone.com/reports/3418616",
        "title": "SMTP CRLF Injection in curl/libcurl via MAIL FROM/RCPT TO parameters",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "jood6383",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-11-10",
        "submittedAt": "2025-11-10",
        "vulnerabilityClass": "injection",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3335709",
      "url": "https://vulns.co/api/v1/reports/hackerone-3335709/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3335709",
      "record": {
        "id": "hackerone-3335709",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3335709",
        "sourceUrl": "https://hackerone.com/reports/3335709",
        "title": "SQL Injection in Django ORM via Unvalidated `_connector` in Q Objects",
        "program": "Django",
        "programUrl": "https://hackerone.com/django",
        "reporter": "cyberstan",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-11-06",
        "submittedAt": "2025-09-12",
        "weakness": "SQL Injection",
        "vulnerabilityClass": "injection",
        "summary": "A critical SQL injection vulnerability was discovered in the Django ORM's handling of Q objects. The internal WhereNode.as_sql method used unsafe string formatting to inject the query connector, which could be controlled by an attacker through the _connector key when creating a Q object. This allowed arbitrary SQL to be injected into the WHERE clause, bypassing the ORM's parameterization safeguards.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3383095",
      "url": "https://vulns.co/api/v1/reports/hackerone-3383095/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3383095",
      "record": {
        "id": "hackerone-3383095",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3383095",
        "sourceUrl": "https://hackerone.com/reports/3383095",
        "title": "DNS Rebinding Attack",
        "program": "arkadiyt-projects",
        "programUrl": "https://hackerone.com/arkadiyt-projects",
        "reporter": "newby99",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-10-19",
        "submittedAt": "2025-10-14",
        "weakness": "Server-Side Request Forgery (SSRF)",
        "vulnerabilityClass": "ssrf",
        "hunterAngle": "Map URL parsing, redirects, DNS resolution, and egress as separate decisions. Use an owned callback and compare it with a non-routable control without probing unrelated internal services.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:research-abello-xs-leak-redirects",
      "url": "https://vulns.co/api/v1/reports/research-abello-xs-leak-redirects/",
      "webUrl": "https://vulns.co/reports/#report-research-abello-xs-leak-redirects",
      "record": {
        "id": "research-abello-xs-leak-redirects",
        "source": "researcher",
        "sourceLabel": "babelo",
        "sourceType": "technique-research",
        "sourceUrl": "https://blog.babelo.xyz/posts/cross-site-subdomain-leak/",
        "title": "XSS-Leak: Leaking Cross-Origin Redirects",
        "program": "Chromium-based browsers",
        "reporter": "Salvatore Abello",
        "severityLabel": "Technique research",
        "severitySystem": "Publication type, not severity",
        "severityBasis": "not-severity",
        "disclosedAt": "2025-09-18",
        "vulnerabilityClass": "browser-client",
        "publishedOutcome": "The author presents a new technique. No program severity is stated.",
        "hunterAngle": "When a sensitive browser action changes network scheduling, test for a measurable oracle without assuming ordinary same-origin analysis is sufficient.",
        "reviewStatus": "canonical-source-reviewed"
      }
    },
    {
      "id": "report:hackerone-3228011",
      "url": "https://vulns.co/api/v1/reports/hackerone-3228011/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3228011",
      "record": {
        "id": "hackerone-3228011",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3228011",
        "sourceUrl": "https://hackerone.com/reports/3228011",
        "title": "Critical Information Disclosure via /talos/api/v1/files/upload",
        "program": "Bykea",
        "programUrl": "https://hackerone.com/bykea",
        "reporter": "sameer_ali",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-09-17",
        "submittedAt": "2025-06-27",
        "weakness": "Inclusion of Sensitive Information in an Include File",
        "vulnerabilityClass": "data-exposure",
        "summary": "A vulnerability was discovered in the file upload functionality, where uploaded files were first stored on the server before being sent to S3. Due to a configuration flaw, memory chunks from the server were included in some uploaded files. This issue was classified as critical and was addressed as a priority.",
        "hunterAngle": "Identify the intended audience and the narrowest unauthorized observer. Use controlled records, distinguish metadata from secret material, and quantify the repeatable exposure boundary.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:research-flomb-http2-connect",
      "url": "https://vulns.co/api/v1/reports/research-flomb-http2-connect/",
      "webUrl": "https://vulns.co/reports/#report-research-flomb-http2-connect",
      "record": {
        "id": "research-flomb-http2-connect",
        "source": "researcher",
        "sourceLabel": "flomb",
        "sourceType": "technique-research",
        "sourceUrl": "https://blog.flomb.net/posts/http2connect/",
        "title": "Playing with HTTP/2 CONNECT",
        "program": "Misconfigured HTTP/2 proxies",
        "reporter": "flomb",
        "severityLabel": "Technique research",
        "severitySystem": "Publication type, not severity",
        "severityBasis": "not-severity",
        "disclosedAt": "2025-09-15",
        "vulnerabilityClass": "request-boundary",
        "publishedOutcome": "No vendor disclosure or severity is stated by the author.",
        "hunterAngle": "In authorized environments, add HTTP/2 CONNECT to proxy capability mapping and distinguish intended forward proxying from unsafe destination controls.",
        "reviewStatus": "canonical-source-reviewed"
      }
    },
    {
      "id": "report:hackerone-3292573",
      "url": "https://vulns.co/api/v1/reports/hackerone-3292573/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3292573",
      "record": {
        "id": "hackerone-3292573",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3292573",
        "sourceUrl": "https://hackerone.com/reports/3292573",
        "title": "SQL Injection when using FilteredRelation",
        "program": "Django",
        "programUrl": "https://hackerone.com/django",
        "reporter": "eyalsec",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-09-15",
        "submittedAt": "2025-08-09",
        "weakness": "SQL Injection",
        "vulnerabilityClass": "injection",
        "summary": "A SQL injection vulnerability was discovered in the Django framework when using the FilteredRelation feature. The vulnerability was located in the tests/filtered_relation/tests.py file. The vulnerability allowed an attacker to inject malicious SQL code through the user_data parameter used in the FilteredRelation and select_related functions.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3228888",
      "url": "https://vulns.co/api/v1/reports/hackerone-3228888/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3228888",
      "record": {
        "id": "hackerone-3228888",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3228888",
        "sourceUrl": "https://hackerone.com/reports/3228888",
        "title": "Account Takeover in Password Reset Function",
        "program": "Mars",
        "programUrl": "https://hackerone.com/mars",
        "reporter": "egsec",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-09-02",
        "submittedAt": "2025-06-28",
        "weakness": "Authentication Bypass",
        "vulnerabilityClass": "identity",
        "summary": "A critical authentication bypass vulnerability was present in the password reset functionality of the website. The vulnerability allowed attackers to take over any user account without requiring access to the victim's phone number or one-time password. The security flaw existed in the implementation of the \"Forgot Password\" feature, where the system relied on client-side responses to determine the success of OTP verification. An attacker could intercept the server response and manipulate it to bypass the OTP verification step entirely, allowing them to set a new password for the victim's account.",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2718253",
      "url": "https://vulns.co/api/v1/reports/hackerone-2718253/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2718253",
      "record": {
        "id": "hackerone-2718253",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2718253",
        "sourceUrl": "https://hackerone.com/reports/2718253",
        "title": "Email verification bypass via request to endpoint \"accounts.insightly.com/signup/provisionuser\"",
        "program": "Insightly",
        "programUrl": "https://hackerone.com/insightly",
        "reporter": "akostak",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-08-18",
        "submittedAt": "2024-09-15",
        "weakness": "Improper Authorization",
        "vulnerabilityClass": "access-control",
        "summary": "The vulnerability allowed bypassing email verification when creating a new Insightly account. The vulnerability existed in the \"EmailAddress\" parameter of the member creation endpoint. By modifying the parameter, an attacker could create a new account using any email address, including those of existing users, effectively taking over their accounts.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3295650",
      "url": "https://vulns.co/api/v1/reports/hackerone-3295650/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3295650",
      "record": {
        "id": "hackerone-3295650",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3295650",
        "sourceUrl": "https://hackerone.com/reports/3295650",
        "title": "Exposure of Hard-coded Private Keys and Credentials in curl Source Repository (CWE-321)",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "spectre-1",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-08-12",
        "submittedAt": "2025-08-12",
        "weakness": "Use of Hard-coded Cryptographic Key",
        "vulnerabilityClass": "code-execution",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3293801",
      "url": "https://vulns.co/api/v1/reports/hackerone-3293801/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3293801",
      "record": {
        "id": "hackerone-3293801",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3293801",
        "sourceUrl": "https://hackerone.com/reports/3293801",
        "title": "Title: Remote Code Execution (RCE) via Arbitrary Library Loading in `--engine` option",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "z1andr4g0n",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-08-10",
        "submittedAt": "2025-08-10",
        "weakness": "Code Injection",
        "vulnerabilityClass": "injection",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3293177",
      "url": "https://vulns.co/api/v1/reports/hackerone-3293177/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3293177",
      "record": {
        "id": "hackerone-3293177",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3293177",
        "sourceUrl": "https://hackerone.com/reports/3293177",
        "title": "Path Traversal in SFTP QUOTE command leads to Arbitrary File Write and potential RCE",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "z1andr4g0n",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-08-10",
        "submittedAt": "2025-08-09",
        "weakness": "Relative Path Traversal",
        "vulnerabilityClass": "code-execution",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:research-kettle-http1-desync-endgame",
      "url": "https://vulns.co/api/v1/reports/research-kettle-http1-desync-endgame/",
      "webUrl": "https://vulns.co/reports/#report-research-kettle-http1-desync-endgame",
      "record": {
        "id": "research-kettle-http1-desync-endgame",
        "source": "researcher",
        "sourceLabel": "PortSwigger Research",
        "sourceType": "technique-research",
        "sourceUrl": "https://portswigger.net/research/http1-must-die",
        "title": "HTTP/1.1 must die: the desync endgame",
        "program": "Akamai, Cloudflare, Netlify, and other case studies",
        "reporter": "James Kettle",
        "severityLabel": "Technique research",
        "severitySystem": "Publication type, not severity",
        "severityBasis": "not-severity",
        "disclosedAt": "2025-08-06",
        "vulnerabilityClass": "request-boundary",
        "publishedOutcome": "The author states the research yielded more than $200,000 in bug bounties in two weeks.",
        "hunterAngle": "Prioritize protocol translation points, especially HTTP/2 to HTTP/1.1 downgrades, and record exact front-end and back-end behavior before impact claims.",
        "reviewStatus": "canonical-source-reviewed"
      }
    },
    {
      "id": "report:hackerone-2831902",
      "url": "https://vulns.co/api/v1/reports/hackerone-2831902/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2831902",
      "record": {
        "id": "hackerone-2831902",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2831902",
        "sourceUrl": "https://hackerone.com/reports/2831902",
        "title": "[CRITICAL] 0-Click Account Takeover via Password Reset [AUTH-3243] /orchestrator/v1/password_reset/start",
        "program": "Remitly",
        "programUrl": "https://hackerone.com/remitly",
        "reporter": "db3wy",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-07-21",
        "submittedAt": "2024-11-10",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "The vulnerability discovered allows an attacker to reset the password of a victim's account without requiring any user interaction or special privileges. By intercepting the password reset request and modifying it with the victim's session data, the attacker can successfully take over the account.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3242087",
      "url": "https://vulns.co/api/v1/reports/hackerone-3242087/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3242087",
      "record": {
        "id": "hackerone-3242087",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3242087",
        "sourceUrl": "https://hackerone.com/reports/3242087",
        "title": "Arbitrary File Read via file:// Protocol in cURL",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "mrtufan",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-07-09",
        "submittedAt": "2025-07-09",
        "weakness": "Path Traversal",
        "vulnerabilityClass": "file-boundary",
        "hunterAngle": "Trace filename, path, content type, storage, and retrieval as separate controls. Use inert files and confirm the smallest boundary violation before testing execution paths.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1813453",
      "url": "https://vulns.co/api/v1/reports/hackerone-1813453/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1813453",
      "record": {
        "id": "hackerone-1813453",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1813453",
        "sourceUrl": "https://hackerone.com/reports/1813453",
        "title": "[MK8DX] Improper ranking/replay file parsing",
        "program": "Nintendo",
        "programUrl": "https://hackerone.com/nintendo",
        "reporter": "crazy_man123",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-07-06",
        "submittedAt": "2022-12-21",
        "weakness": "Memory Corruption - Generic",
        "vulnerabilityClass": "critical-path",
        "summary": "The vulnerability in the Mario Kart 8 Deluxe game involved improper ranking and replay file parsing. This allowed for potential exploitation, leading to potentially unintended consequences.",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2976481",
      "url": "https://vulns.co/api/v1/reports/hackerone-2976481/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2976481",
      "record": {
        "id": "hackerone-2976481",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2976481",
        "sourceUrl": "https://hackerone.com/reports/2976481",
        "title": "Unauthorized coins transfer from locking account(s)",
        "program": "Cosmos",
        "programUrl": "https://hackerone.com/cosmos",
        "reporter": "unknown_feature",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-06-29",
        "submittedAt": "2025-02-06",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "The Cosmos SDK was found to have a vulnerability that allowed unauthorized transfer of funds from locking accounts. The issue was specifically identified in the `periodic-locking-account`, but it was believed to affect other locking account types as well. The vulnerability stemmed from the way the `SendCoins` function validated the sender's identity, which could be bypassed when the message was packed into a `MsgExecute` transaction. This allowed an attacker to transfer funds from a locking account they did not own, if the account had unlocked funds after the locking period had ended.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3101127",
      "url": "https://vulns.co/api/v1/reports/hackerone-3101127/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3101127",
      "record": {
        "id": "hackerone-3101127",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3101127",
        "sourceUrl": "https://hackerone.com/reports/3101127",
        "title": "Buffer Overflow in curl MQTT Test Server (tests/server/mqttd.c) via Malicious CONNECT Packet",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "drdee-hackerone",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-06-28",
        "submittedAt": "2025-04-19",
        "weakness": "Memory Corruption - Generic",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3030158",
      "url": "https://vulns.co/api/v1/reports/hackerone-3030158/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3030158",
      "record": {
        "id": "hackerone-3030158",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3030158",
        "sourceUrl": "https://hackerone.com/reports/3030158",
        "title": "Improper Restriction of Authentication Attempts in cURL",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "irfanmughal1122",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-06-28",
        "submittedAt": "2025-03-10",
        "weakness": "Improper Restriction of Authentication Attempts",
        "vulnerabilityClass": "identity",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2819573",
      "url": "https://vulns.co/api/v1/reports/hackerone-2819573/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2819573",
      "record": {
        "id": "hackerone-2819573",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2819573",
        "sourceUrl": "https://hackerone.com/reports/2819573",
        "title": "Mutation Based Stored XSS on Trix Editor version latest (2.1.8)",
        "program": "Basecamp",
        "programUrl": "https://hackerone.com/basecamp",
        "reporter": "sudi",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-06-27",
        "submittedAt": "2024-11-04",
        "vulnerabilityClass": "browser-injection",
        "summary": "A vulnerability was discovered in the Trix Editor version 2.1.8 where a mutation-based stored cross-site scripting (XSS) attack was possible. The vulnerability could be exploited by crafting a malicious payload that, when copied and pasted into the editor, would trigger the execution of arbitrary JavaScript code.",
        "hunterAngle": "Locate the exact browser sink and encoding context. Prove execution with a harmless marker, then test whether privilege, origin, or persistence changes the impact.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:research-shah-ssrf-redirect-loops",
      "url": "https://vulns.co/api/v1/reports/research-shah-ssrf-redirect-loops/",
      "webUrl": "https://vulns.co/reports/#report-research-shah-ssrf-redirect-loops",
      "record": {
        "id": "research-shah-ssrf-redirect-loops",
        "source": "researcher",
        "sourceLabel": "SL Cyber",
        "sourceType": "technique-research",
        "sourceUrl": "https://slcyber.io/research-center/novel-ssrf-technique-involving-http-redirect-loops/",
        "title": "Novel SSRF Technique Involving HTTP Redirect Loops",
        "program": "Unnamed enterprise product and similar HTTP clients",
        "reporter": "Shubham Shah",
        "severityLabel": "Technique research",
        "severitySystem": "Publication type, not severity",
        "severityBasis": "not-severity",
        "disclosedAt": "2025-06-23",
        "vulnerabilityClass": "request-boundary",
        "publishedOutcome": "The author states the technique obtained AWS metadata credentials in the affected product. No universal severity is stated.",
        "hunterAngle": "For an authorized blind SSRF lead, document redirect count, status handling, and error differences before escalating impact.",
        "reviewStatus": "canonical-source-reviewed"
      }
    },
    {
      "id": "report:research-slonser-self-xss",
      "url": "https://vulns.co/api/v1/reports/research-slonser-self-xss/",
      "webUrl": "https://vulns.co/reports/#report-research-slonser-self-xss",
      "record": {
        "id": "research-slonser-self-xss",
        "source": "researcher",
        "sourceLabel": "Slonser",
        "sourceType": "technique-research",
        "sourceUrl": "https://blog.slonser.info/posts/make-self-xss-great-again/",
        "title": "Make Self-XSS Great Again",
        "program": "Modern browser credentialless-frame behavior",
        "reporter": "Slonser",
        "severityLabel": "Technique research",
        "severitySystem": "Publication type, not severity",
        "severityBasis": "not-severity",
        "disclosedAt": "2025-06-13",
        "vulnerabilityClass": "browser-client",
        "publishedOutcome": "The author presents an authorized-testing technique and no universal vendor severity.",
        "hunterAngle": "Assess whether nominal self-XSS has a cross-account execution path only after checking framing policy, login CSRF defenses, and current browser behavior.",
        "reviewStatus": "canonical-source-reviewed"
      }
    },
    {
      "id": "report:research-brutecat-google-phone-leak",
      "url": "https://vulns.co/api/v1/reports/research-brutecat-google-phone-leak/",
      "webUrl": "https://vulns.co/reports/#report-research-brutecat-google-phone-leak",
      "record": {
        "id": "research-brutecat-google-phone-leak",
        "source": "researcher",
        "sourceLabel": "Brutecat",
        "sourceType": "program-disclosure",
        "sourceUrl": "https://brutecat.com/articles/leaking-google-phones/",
        "title": "Leaking the phone number of any Google user",
        "program": "Google account recovery",
        "reporter": "Brutecat",
        "severityLabel": "Program disclosure",
        "severitySystem": "Publication type, not severity",
        "severityBasis": "not-severity",
        "disclosedAt": "2025-06-09",
        "vulnerabilityClass": "identity",
        "publishedOutcome": "The author reports broad exposure under the article's stated conditions; Vulns.co does not independently generalize its reach or infer a severity.",
        "hunterAngle": "Compare client-enforced limits, address-family handling, and deprecated recovery surfaces instead of treating a visible CAPTCHA as the whole control.",
        "reviewStatus": "canonical-source-reviewed"
      }
    },
    {
      "id": "report:hackerone-3165242",
      "url": "https://vulns.co/api/v1/reports/hackerone-3165242/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3165242",
      "record": {
        "id": "hackerone-3165242",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3165242",
        "sourceUrl": "https://hackerone.com/reports/3165242",
        "title": "Server-Side Request Forgery (SSRF) via Game Export API",
        "program": "Lichess",
        "programUrl": "https://hackerone.com/lichess",
        "reporter": "oblivionsage",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-06-03",
        "submittedAt": "2025-05-28",
        "weakness": "Server-Side Request Forgery (SSRF)",
        "vulnerabilityClass": "ssrf",
        "summary": "The Lichess game export API was found to be vulnerable to Server-Side Request Forgery (SSRF) due to insufficient input validation of the \"players\" parameter. This allowed an attacker to make the Lichess server send arbitrary HTTP requests to external URLs, potentially exposing sensitive information.",
        "hunterAngle": "Map URL parsing, redirects, DNS resolution, and egress as separate decisions. Use an owned callback and compare it with a non-routable control without probing unrelated internal services.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2828641",
      "url": "https://vulns.co/api/v1/reports/hackerone-2828641/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2828641",
      "record": {
        "id": "hackerone-2828641",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2828641",
        "sourceUrl": "https://hackerone.com/reports/2828641",
        "title": "unauthorized access and add user and change personal information all users",
        "program": "Mars",
        "programUrl": "https://hackerone.com/mars",
        "reporter": "bughunter0x7",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-05-27",
        "submittedAt": "2024-11-07",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "The report describes a vulnerability in the ██████████ website, where unauthorized access to an API endpoint allowed attackers to add new users and modify personal information of existing users. The vulnerability was classified as Improper Access Control. The issue stemmed from the absence of proper authentication and authorization mechanisms on the ██████████ endpoint, which handled user registration and profile updates. This vulnerability allowed anyone to create new user accounts or modify existing user information without requiring any authentication. Additionally, the vulnerability was compounded by a predictable user identifier system (4-digit codes) that could be easily enumerated through brute force methods to identify valid user profiles through the ██████████ endpoint.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:research-kaufman-google-logo-ligature",
      "url": "https://vulns.co/api/v1/reports/research-kaufman-google-logo-ligature/",
      "webUrl": "https://vulns.co/reports/#report-research-kaufman-google-logo-ligature",
      "record": {
        "id": "research-kaufman-google-logo-ligature",
        "source": "researcher",
        "sourceLabel": "Jeff Kaufman",
        "sourceType": "security-note",
        "sourceUrl": "https://www.jefftk.com/p/google-logo-ligature-bug",
        "title": "Google Logo Ligature Bug",
        "program": "Google Sans rendering of attacker-controlled text",
        "reporter": "Jeff Kaufman",
        "severityLabel": "Security note",
        "severitySystem": "Publication type, not severity",
        "severityBasis": "not-severity",
        "disclosedAt": "2025-05-17",
        "vulnerabilityClass": "browser-client",
        "publishedOutcome": "The author calls it an interesting security bug. No CVE, severity, or bounty is stated.",
        "hunterAngle": "Include custom fonts, text rendering, punycode, Unicode normalization, and visual-identity surfaces in phishing-resistance reviews.",
        "reviewStatus": "canonical-source-reviewed"
      }
    },
    {
      "id": "report:hackerone-3085889",
      "url": "https://vulns.co/api/v1/reports/hackerone-3085889/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3085889",
      "record": {
        "id": "hackerone-3085889",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3085889",
        "sourceUrl": "https://hackerone.com/reports/3085889",
        "title": "Weak Rate Limiting Controls in the (LOGIN) page Expose System to Brute Force and DoS Attacks",
        "program": "Lichess",
        "programUrl": "https://hackerone.com/lichess",
        "reporter": "hajjaj0x",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-05-15",
        "submittedAt": "2025-04-09",
        "vulnerabilityClass": "code-execution",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3062122",
      "url": "https://vulns.co/api/v1/reports/hackerone-3062122/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3062122",
      "record": {
        "id": "hackerone-3062122",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3062122",
        "sourceUrl": "https://hackerone.com/reports/3062122",
        "title": "[Xenoblade Chronicles X: Definitive Edition] Unrestricted RPCs allow DoS and writing arbitrary flags remotely",
        "program": "Nintendo",
        "programUrl": "https://hackerone.com/nintendo",
        "reporter": "roccodev",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-05-15",
        "submittedAt": "2025-03-31",
        "weakness": "Resource Injection",
        "vulnerabilityClass": "injection",
        "summary": "The Xenoblade Chronicles X: Definitive Edition vulnerability allowed attackers to perform Denial-of-Service (DoS) attacks and write arbitrary flags remotely due to unrestricted Remote Procedure Calls (RPCs).",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2915647",
      "url": "https://vulns.co/api/v1/reports/hackerone-2915647/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2915647",
      "record": {
        "id": "hackerone-2915647",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2915647",
        "sourceUrl": "https://hackerone.com/reports/2915647",
        "title": "Netlify Authentication Token Exposed in Public Mozilla CI Logs",
        "program": "Mozilla",
        "programUrl": "https://hackerone.com/mozilla",
        "reporter": "samirsec0x01",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-05-13",
        "submittedAt": "2024-12-27",
        "weakness": "Information Disclosure",
        "vulnerabilityClass": "identity",
        "summary": "A critical vulnerability was discovered involving the exposure of a Netlify authentication token within publicly accessible logs. The token provided full access to the \"Mozilla IT Web SRE\" Netlify account, bypassing all restrictions. The token's permissions encompassed roles such as Owner, Developer, Billing Admin, Reviewer, Publisher, and Content Editor, granting complete control over site management, deployments, billing, and content configurations.",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3090123",
      "url": "https://vulns.co/api/v1/reports/hackerone-3090123/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3090123",
      "record": {
        "id": "hackerone-3090123",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3090123",
        "sourceUrl": "https://hackerone.com/reports/3090123",
        "title": "insecure deserilize object leads to RCE On Sitecore (CVE-██████████-27218)",
        "program": "Mars",
        "programUrl": "https://hackerone.com/mars",
        "reporter": "the_reinhardt",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-05-12",
        "submittedAt": "2025-04-12",
        "weakness": "Deserialization of Untrusted Data",
        "vulnerabilityClass": "code-execution",
        "cves": [
          "CVE-2025-27218"
        ],
        "summary": "This critical vulnerability involved an insecure deserialization issue in Sitecore implementation, which was assigned CVE-2025-27218. The vulnerability allowed remote code execution through unsanitized user input in the ThumbnailsAccessToken header. The vulnerability was remediated by removing public access to the affected site, which was then protected behind Cloudflare WAF.",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2828693",
      "url": "https://vulns.co/api/v1/reports/hackerone-2828693/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2828693",
      "record": {
        "id": "hackerone-2828693",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2828693",
        "sourceUrl": "https://hackerone.com/reports/2828693",
        "title": "change part of personal information all users",
        "program": "Mars",
        "programUrl": "https://hackerone.com/mars",
        "reporter": "bughunter0x7",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-05-12",
        "submittedAt": "2024-11-08",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "The report describes a vulnerability in the ██████████ website, where unauthorized access to an API endpoint allowed attackers to add new users and modify personal information of existing users. The vulnerability was classified as Improper Access Control. The issue stemmed from the absence of proper authentication and authorization mechanisms on the ██████████ endpoint, which handled user registration and profile updates. This vulnerability allowed anyone to create new user accounts or modify existing user information without requiring any authentication. Additionally, the vulnerability was compounded by a predictable user identifier system (4-digit codes) that could be easily enumerated through brute force methods to identify valid user profiles through the ██████████ endpoint.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3080597",
      "url": "https://vulns.co/api/v1/reports/hackerone-3080597/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3080597",
      "record": {
        "id": "hackerone-3080597",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3080597",
        "sourceUrl": "https://hackerone.com/reports/3080597",
        "title": "Unauthorized Account Access via Leaked Credentials in URL Format (Account Takeover )",
        "program": "Khan Academy",
        "programUrl": "https://hackerone.com/khanacademy",
        "reporter": "firec4t",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-05-07",
        "submittedAt": "2025-04-07",
        "weakness": "Cleartext Storage of Sensitive Information",
        "vulnerabilityClass": "identity",
        "summary": "The vulnerability allowed attackers to access user accounts on khanAcademy.com using leaked credentials that were publicly available. The credentials were found in clear text format on a third-party website. By entering the email and password, the attacker could perform an account takeover without the user's knowledge or any secondary verification.",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3060373",
      "url": "https://vulns.co/api/v1/reports/hackerone-3060373/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3060373",
      "record": {
        "id": "hackerone-3060373",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3060373",
        "sourceUrl": "https://hackerone.com/reports/3060373",
        "title": "Path Traversal Vulnerability found on IBM Cloud",
        "program": "IBM",
        "programUrl": "https://hackerone.com/ibm",
        "reporter": "0xnullbytex0",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-05-07",
        "submittedAt": "2025-03-26",
        "weakness": "Path Traversal",
        "vulnerabilityClass": "file-boundary",
        "summary": "The path traversal vulnerability on IBM Cloud was reported by an external researcher, analyzed, and remediated. The vulnerability has been addressed.",
        "hunterAngle": "Trace filename, path, content type, storage, and retrieval as separate controls. Use inert files and confirm the smallest boundary violation before testing execution paths.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3088290",
      "url": "https://vulns.co/api/v1/reports/hackerone-3088290/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3088290",
      "record": {
        "id": "hackerone-3088290",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3088290",
        "sourceUrl": "https://hackerone.com/reports/3088290",
        "title": "Middleware Authentication Bypass on IBM Portal",
        "program": "IBM",
        "programUrl": "https://hackerone.com/ibm",
        "reporter": "muhammadwaseem3",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-05-02",
        "submittedAt": "2025-04-11",
        "weakness": "Command Injection - Generic",
        "vulnerabilityClass": "injection",
        "cves": [
          "CVE-2025-29927"
        ],
        "summary": "The vulnerability of middleware authentication bypass on the IBM Portal endpoint was reported, analyzed, and remediated. The discovery was reported by an external researcher.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3103849",
      "url": "https://vulns.co/api/v1/reports/hackerone-3103849/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3103849",
      "record": {
        "id": "hackerone-3103849",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3103849",
        "sourceUrl": "https://hackerone.com/reports/3103849",
        "title": "Privilege Escalation leads to Unauthorized Access to Private Conversations By any Regular user [Read , Edit and Delete]",
        "program": "Dust",
        "programUrl": "https://hackerone.com/dust",
        "reporter": "0xsom3a",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-04-29",
        "submittedAt": "2025-04-22",
        "weakness": "Privilege Escalation",
        "vulnerabilityClass": "access-control",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2858802",
      "url": "https://vulns.co/api/v1/reports/hackerone-2858802/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2858802",
      "record": {
        "id": "hackerone-2858802",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2858802",
        "sourceUrl": "https://hackerone.com/reports/2858802",
        "title": "low-level p2p ping + tcp flooding leads to a remote crash in monerod",
        "program": "Monero",
        "programUrl": "https://hackerone.com/monero",
        "reporter": "padillac",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-04-14",
        "submittedAt": "2024-11-21",
        "vulnerabilityClass": "critical-path",
        "summary": "The vulnerability allowed remote crashes of the P2P daemon through low-level ping and TCP flooding.",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3068485",
      "url": "https://vulns.co/api/v1/reports/hackerone-3068485/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3068485",
      "record": {
        "id": "hackerone-3068485",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3068485",
        "sourceUrl": "https://hackerone.com/reports/3068485",
        "title": "Direct IP Access to Website",
        "program": "Lichess",
        "programUrl": "https://hackerone.com/lichess",
        "reporter": "ryomenshuvro",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-04-11",
        "submittedAt": "2025-03-31",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3000510",
      "url": "https://vulns.co/api/v1/reports/hackerone-3000510/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3000510",
      "record": {
        "id": "hackerone-3000510",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3000510",
        "sourceUrl": "https://hackerone.com/reports/3000510",
        "title": "The /reports/:id.json endpoint discloses potentially sensitive user attributes when reporter summary is present",
        "program": "HackerOne",
        "programUrl": "https://hackerone.com/security",
        "reporter": "avinash_",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-04-01",
        "submittedAt": "2025-02-19",
        "weakness": "Information Disclosure",
        "vulnerabilityClass": "data-exposure",
        "summary": "The /reports/:id.json endpoint disclosed potentially sensitive user attributes, including the reporter's email, OTP backup codes, phone number, graphql_secret_token, and t-shirt size when a reporter summary was present.",
        "hunterAngle": "Identify the intended audience and the narrowest unauthorized observer. Use controlled records, distinguish metadata from secret material, and quantify the repeatable exposure boundary.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-3024673",
      "url": "https://vulns.co/api/v1/reports/hackerone-3024673/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-3024673",
      "record": {
        "id": "hackerone-3024673",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "3024673",
        "sourceUrl": "https://hackerone.com/reports/3024673",
        "title": "SSRF in Autodesk Rendering leading to account takeover",
        "program": "Autodesk",
        "programUrl": "https://hackerone.com/autodesk",
        "reporter": "metereorpreter",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-03-18",
        "submittedAt": "2025-03-06",
        "weakness": "Server-Side Request Forgery (SSRF)",
        "vulnerabilityClass": "ssrf",
        "summary": "A server side request forgery (SSRF) vulnerability was discovered in Autodesk Rendering. The vulnerability could have allowed an attacker to gain control of a victim's account while they were logged in. Autodesk has fixed the vulnerability.",
        "hunterAngle": "Map URL parsing, redirects, DNS resolution, and egress as separate decisions. Use an owned callback and compare it with a non-routable control without probing unrelated internal services.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:research-brutecat-youtube-creator-emails",
      "url": "https://vulns.co/api/v1/reports/research-brutecat-youtube-creator-emails/",
      "webUrl": "https://vulns.co/reports/#report-research-brutecat-youtube-creator-emails",
      "record": {
        "id": "research-brutecat-youtube-creator-emails",
        "source": "researcher",
        "sourceLabel": "Brutecat",
        "sourceType": "program-disclosure",
        "sourceUrl": "https://brutecat.com/articles/youtube-creator-emails/",
        "title": "Disclosing YouTube Creator Emails for a $20k Bounty",
        "program": "YouTube creators",
        "reporter": "Brutecat",
        "severityLabel": "Program disclosure",
        "severitySystem": "Publication type, not severity",
        "severityBasis": "not-severity",
        "disclosedAt": "2025-03-13",
        "vulnerabilityClass": "data-exposure",
        "publishedOutcome": "$20,000 bounty, as stated by the author.",
        "hunterAngle": "When public and private representations of the same object differ, enumerate the representation boundaries and undocumented parameters.",
        "reviewStatus": "canonical-source-reviewed"
      }
    },
    {
      "id": "report:hackerone-2958619",
      "url": "https://vulns.co/api/v1/reports/hackerone-2958619/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2958619",
      "record": {
        "id": "hackerone-2958619",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2958619",
        "sourceUrl": "https://hackerone.com/reports/2958619",
        "title": "SQLi | in URL paths",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "almuntadhar0x01",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-03-06",
        "submittedAt": "2025-01-26",
        "weakness": "SQL Injection",
        "vulnerabilityClass": "injection",
        "summary": "The vulnerability summary is as follows: A SQL injection vulnerability was discovered in the customerId parameter of the URL path. The vulnerability was demonstrated by adding a quote in the customerId parameter, which resulted in an error indicating that the application was vulnerable to SQL injection attacks. Exploitation of this vulnerability could have allowed an attacker to access and download the database, potentially exposing user information.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2495989",
      "url": "https://vulns.co/api/v1/reports/hackerone-2495989/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2495989",
      "record": {
        "id": "hackerone-2495989",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2495989",
        "sourceUrl": "https://hackerone.com/reports/2495989",
        "title": "Sale cancellations from other sellers without restrictions",
        "program": "MercadoLibre",
        "programUrl": "https://hackerone.com/mercadolibre",
        "reporter": "capablanca0",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-03-06",
        "submittedAt": "2024-05-08",
        "weakness": "Insecure Direct Object Reference (IDOR)",
        "vulnerabilityClass": "access-control",
        "summary": "A vulnerability that allowed sale cancellations from other sellers without restrictions was reported and acknowledged by the platform. A fix was implemented internally.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2762462",
      "url": "https://vulns.co/api/v1/reports/hackerone-2762462/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2762462",
      "record": {
        "id": "hackerone-2762462",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2762462",
        "sourceUrl": "https://hackerone.com/reports/2762462",
        "title": "Ability to Add and Verify Uncontrolled Mobile Numbers Leading to Account Takeover (ATO)",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "trev0ck",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-03-04",
        "submittedAt": "2024-10-07",
        "weakness": "Authentication Bypass Using an Alternate Path or Channel",
        "vulnerabilityClass": "identity",
        "summary": "The vulnerability allowed attackers to manipulate the OTP verification response to bypass the OTP check and link an uncontrolled mobile number to the victim's account. This led to an account takeover scenario where the attacker gained full access to the victim's account without controlling the victim's phone number.",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2801787",
      "url": "https://vulns.co/api/v1/reports/hackerone-2801787/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2801787",
      "record": {
        "id": "hackerone-2801787",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2801787",
        "sourceUrl": "https://hackerone.com/reports/2801787",
        "title": "Admin Dashboard Access Leads to Updating Merchant Info",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "tinopreter",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-03-02",
        "submittedAt": "2024-10-24",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "The application had a hidden registration endpoint that allowed an unauthorized user to sign up for an admin portal. This granted the user access to the admin dashboard, where they could view, edit, and delete information for registered merchants, cashiers, stations, and supervisors.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2293343",
      "url": "https://vulns.co/api/v1/reports/hackerone-2293343/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2293343",
      "record": {
        "id": "hackerone-2293343",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2293343",
        "sourceUrl": "https://hackerone.com/reports/2293343",
        "title": "Account Takeover via Password Reset without user interactions",
        "program": "GitLab",
        "programUrl": "https://hackerone.com/gitlab",
        "reporter": "asterion04",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-02-26",
        "submittedAt": "2023-12-20",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "bounty": {
          "value": 35000,
          "currency": "USD"
        },
        "summary": "The report submitted to GitLab described a vulnerability that allowed account takeover via the password reset form. The vulnerability was triggered by modifying the JSON request to include the victim's email along with the attacker's email. This resulted in the password reset email being sent to both emails, allowing the attacker to access the victim's account by using the reset link.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2450685",
      "url": "https://vulns.co/api/v1/reports/hackerone-2450685/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2450685",
      "record": {
        "id": "hackerone-2450685",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2450685",
        "sourceUrl": "https://hackerone.com/reports/2450685",
        "title": "Unauthorized access to PII leads to Administrator account Takeover",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "h0w",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-02-22",
        "submittedAt": "2024-04-06",
        "weakness": "Privilege Escalation",
        "vulnerabilityClass": "access-control",
        "summary": "The vulnerability arises from insufficient restrictions placed on the list of post authors, which could be exploited by remote attackers to obtain sensitive information through wp/v2/users/15 requests. The sensitive information, including email addresses, could be obtained and used in further attacks such as password guessing. A CORS misconfiguration was also identified, which may have enabled third-party sites to carry out privileged actions and retrieve sensitive information.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2778350",
      "url": "https://vulns.co/api/v1/reports/hackerone-2778350/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2778350",
      "record": {
        "id": "hackerone-2778350",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2778350",
        "sourceUrl": "https://hackerone.com/reports/2778350",
        "title": "Cisco IOS XE instance at ████ vulnerable to CVE-██████",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "odaysec",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-02-19",
        "submittedAt": "2024-10-12",
        "weakness": "Command Injection - Generic",
        "vulnerabilityClass": "injection",
        "cves": [
          "CVE-2023-20198",
          "CVE-2023-20273"
        ],
        "summary": "A vulnerability was discovered in a Cisco IOS XE instance that allowed bypassing authentication to reach a web endpoint and execute arbitrary Cisco IOS commands or make configuration changes with Privilege 15 privileges. The vulnerability was characterized by improper path validation to bypass filtering and access the webui_wsma_http endpoint. Further exploitation leveraged another vulnerability to escalate to the underlying Linux OS root user.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:research-brutecat-youtube-user-emails",
      "url": "https://vulns.co/api/v1/reports/research-brutecat-youtube-user-emails/",
      "webUrl": "https://vulns.co/reports/#report-research-brutecat-youtube-user-emails",
      "record": {
        "id": "research-brutecat-youtube-user-emails",
        "source": "researcher",
        "sourceLabel": "Brutecat",
        "sourceType": "program-disclosure",
        "sourceUrl": "https://brutecat.com/articles/leaking-youtube-emails/",
        "title": "Leaking the email of any YouTube user for $10,000",
        "program": "YouTube",
        "reporter": "Brutecat",
        "severityLabel": "Program disclosure",
        "severitySystem": "Publication type, not severity",
        "severityBasis": "not-severity",
        "disclosedAt": "2025-02-12",
        "vulnerabilityClass": "data-exposure",
        "publishedOutcome": "$10,000 bounty, as stated by the author.",
        "hunterAngle": "Model identity joins across services and test only public, in-scope paths where one identifier can become a more sensitive identifier.",
        "reviewStatus": "canonical-source-reviewed"
      }
    },
    {
      "id": "report:hackerone-2981756",
      "url": "https://vulns.co/api/v1/reports/hackerone-2981756/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2981756",
      "record": {
        "id": "hackerone-2981756",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2981756",
        "sourceUrl": "https://hackerone.com/reports/2981756",
        "title": "Wordpress users Disclosure",
        "program": "Autodesk",
        "programUrl": "https://hackerone.com/autodesk",
        "reporter": "karimtantawy",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-02-12",
        "submittedAt": "2025-02-08",
        "weakness": "Information Disclosure",
        "vulnerabilityClass": "data-exposure",
        "hunterAngle": "Identify the intended audience and the narrowest unauthorized observer. Use controlled records, distinguish metadata from secret material, and quantify the repeatable exposure boundary.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2950536",
      "url": "https://vulns.co/api/v1/reports/hackerone-2950536/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2950536",
      "record": {
        "id": "hackerone-2950536",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2950536",
        "sourceUrl": "https://hackerone.com/reports/2950536",
        "title": "Applicant security exam Attachments/Documents accessible through an IDOR/BAC on the custom Apex controller on https://█████.mil",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "oxylis",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-02-12",
        "submittedAt": "2025-01-20",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "The applicant security exam contained an Insecure Direct Object Reference (IDOR) vulnerability on the custom Apex controller on the https://█████.mil portal. The vulnerability allowed an attacker to switch the ownership of any Attachment record and access the files, which contained sensitive information such as personal medical records submitted as part of the vetting procedures.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2846011",
      "url": "https://vulns.co/api/v1/reports/hackerone-2846011/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2846011",
      "record": {
        "id": "hackerone-2846011",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2846011",
        "sourceUrl": "https://hackerone.com/reports/2846011",
        "title": "XSS on using the legacy \"Graphie To Png\" API",
        "program": "Khan Academy",
        "programUrl": "https://hackerone.com/khanacademy",
        "reporter": "sikn",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-02-06",
        "submittedAt": "2024-11-18",
        "weakness": "Cross-site Scripting (XSS) - DOM",
        "vulnerabilityClass": "browser-injection",
        "summary": "The legacy \"Graphie To Png\" API was vulnerable to exploitation. An attacker could upload malicious graphies that included harmful SVG and JSON data. The SVG contained an `onload` attribute that executed arbitrary JavaScript. The JSON data modified the content of labels, causing the graphie renderer to inject the attacker's code into the DOM.",
        "hunterAngle": "Locate the exact browser sink and encoding context. Prove execution with a harmless marker, then test whether privilege, origin, or persistence changes the impact.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2954547",
      "url": "https://vulns.co/api/v1/reports/hackerone-2954547/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2954547",
      "record": {
        "id": "hackerone-2954547",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2954547",
        "sourceUrl": "https://hackerone.com/reports/2954547",
        "title": "Weak credentials found in Jenkins endpoint",
        "program": "IBM",
        "programUrl": "https://hackerone.com/ibm",
        "reporter": "roswell-47",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-02-05",
        "submittedAt": "2025-01-23",
        "vulnerabilityClass": "critical-path",
        "summary": "Weak credentials were discovered in a Jenkins endpoint. The issue was reported to IBM, analyzed, and remediated.",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2926447",
      "url": "https://vulns.co/api/v1/reports/hackerone-2926447/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2926447",
      "record": {
        "id": "hackerone-2926447",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2926447",
        "sourceUrl": "https://hackerone.com/reports/2926447",
        "title": "Public google drive link Exposes Military Orders Containing PII (Name, SSN etc..) and Operational Details",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "entropydrifter",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-01-24",
        "submittedAt": "2025-01-07",
        "weakness": "Information Disclosure",
        "vulnerabilityClass": "data-exposure",
        "summary": "A public Google Drive link was found that exposed military orders containing personally identifiable information (PII) such as full names, Social Security numbers, home addresses, and security clearance levels. The vulnerability was discovered on a website located at \"https://████████.aspx?Mode=ReadOnly&Id=90dd0d3b-0ed1-e76b-128f-11ebc799ba55\".",
        "hunterAngle": "Identify the intended audience and the narrowest unauthorized observer. Use controlled records, distinguish metadata from secret material, and quantify the repeatable exposure boundary.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1556950",
      "url": "https://vulns.co/api/v1/reports/hackerone-1556950/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1556950",
      "record": {
        "id": "hackerone-1556950",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1556950",
        "sourceUrl": "https://hackerone.com/reports/1556950",
        "title": "Exposure of Private Personal Information to an Unauthorized Actor - PII and soldier data (mos, schools, and speciality training)",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "hxhbrofessor",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-01-24",
        "submittedAt": "2022-05-03",
        "weakness": "Violation of Secure Design Principles",
        "vulnerabilityClass": "critical-path",
        "summary": "The vulnerability exposed private personal information of soldiers, including their last four digits of Social Security number, home of record, military occupation specialty, and school records, to unauthorized users on the `https://█████████/SelfService/home/selfservice` website. The vulnerability allowed authenticated users to manipulate URL requests to access the personal information of other soldiers.",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1618347",
      "url": "https://vulns.co/api/v1/reports/hackerone-1618347/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1618347",
      "record": {
        "id": "hackerone-1618347",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1618347",
        "sourceUrl": "https://hackerone.com/reports/1618347",
        "title": "Disclosing PolicyPageAssetGroup in Private Programs via /graphql `gid://hackerone/PolicyPageAssetGroupsIndex::PolicyPageAssetGroup/{id}`",
        "program": "HackerOne",
        "programUrl": "https://hackerone.com/security",
        "reporter": "haxta4ok00",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-01-21",
        "submittedAt": "2022-06-28",
        "vulnerabilityClass": "critical-path",
        "bounty": {
          "value": 25000,
          "currency": "USD"
        },
        "summary": "The vulnerability allowed unauthorized users to retrieve sensitive information about private bug bounty programs on HackerOne, including program names, scope details, and the titles of reports. The issue was promptly addressed by the HackerOne team, who recognized its critical severity and awarded a generous bounty for its discovery.",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1707287",
      "url": "https://vulns.co/api/v1/reports/hackerone-1707287/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1707287",
      "record": {
        "id": "hackerone-1707287",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1707287",
        "sourceUrl": "https://hackerone.com/reports/1707287",
        "title": "CVE-2022-40604: Apache Airflow: Format String Vulnerability",
        "program": "Internet Bug Bounty",
        "programUrl": "https://hackerone.com/ibb",
        "reporter": "leixiao",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-01-18",
        "submittedAt": "2022-09-21",
        "weakness": "Use of Externally-Controlled Format String",
        "vulnerabilityClass": "critical-path",
        "cves": [
          "CVE-2022-40604"
        ],
        "bounty": {
          "value": 8000,
          "currency": "USD"
        },
        "summary": "There is a format string vulnerability in Apache Airflow versions 2.3.0 through 2.3.4 in the src/airflow/utils/log/file_task_handler.py file. The vulnerability was caused by unnecessary formatting of a URL, which could allow for information extraction.",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2817658",
      "url": "https://vulns.co/api/v1/reports/hackerone-2817658/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2817658",
      "record": {
        "id": "hackerone-2817658",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2817658",
        "sourceUrl": "https://hackerone.com/reports/2817658",
        "title": "Unauthenticated Path Traversal and Command Injection in Trellix Enterprise Security Manager 11.6.10",
        "program": "Trellix",
        "programUrl": "https://hackerone.com/trellix",
        "reporter": "r4v",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-01-12",
        "submittedAt": "2024-11-02",
        "weakness": "OS Command Injection",
        "vulnerabilityClass": "injection",
        "summary": "A critical vulnerability was identified in Trellix Enterprise Security Manager (ESM) version 11.6.10. The vulnerability allowed unauthenticated access to internal API endpoints through path traversal and enabled remote code execution via command injection. The issue stemmed from insecure AJP proxy configuration and lack of input validation. The vulnerability has been confirmed on the publicly available trial version.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2635315",
      "url": "https://vulns.co/api/v1/reports/hackerone-2635315/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2635315",
      "record": {
        "id": "hackerone-2635315",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2635315",
        "sourceUrl": "https://hackerone.com/reports/2635315",
        "title": "Yet Another OTP code Leaked in the API Response",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "tinopreter",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-01-08",
        "submittedAt": "2024-08-01",
        "weakness": "Improper Authentication - Generic",
        "vulnerabilityClass": "identity",
        "summary": "The OTP code was leaked in the API response, which compromised the purpose of its implementation. The application requested a phone number for authentication and sent an OTP code to the user, but the OTP was returned in the API response, exposing it to potential misuse.",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2633959",
      "url": "https://vulns.co/api/v1/reports/hackerone-2633959/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2633959",
      "record": {
        "id": "hackerone-2633959",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2633959",
        "sourceUrl": "https://hackerone.com/reports/2633959",
        "title": "SQL injection in URL path leads to Database Access",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "tinopreter",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-01-08",
        "submittedAt": "2024-07-31",
        "weakness": "SQL Injection",
        "vulnerabilityClass": "injection",
        "summary": "The application https://corporate.admyntec.co.za/ was found to have an SQL injection vulnerability in its URL paths. User IDs, organization numbers, and other sensitive information were stored in the backend database without proper sanitization, allowing an attacker to exploit the vulnerability and potentially gain unauthorized access to the database.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2633888",
      "url": "https://vulns.co/api/v1/reports/hackerone-2633888/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2633888",
      "record": {
        "id": "hackerone-2633888",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2633888",
        "sourceUrl": "https://hackerone.com/reports/2633888",
        "title": "OTP code Leaked in API Response",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "tinopreter",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2025-01-08",
        "submittedAt": "2024-07-31",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "The application allowed users to sign up for device insurance. When getting a quote, an OTP code was sent to the user's phone number for authentication, but the same OTP code was also returned in the API response.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:research-zhero-nextjs-cache-chains",
      "url": "https://vulns.co/api/v1/reports/research-zhero-nextjs-cache-chains/",
      "webUrl": "https://vulns.co/reports/#report-research-zhero-nextjs-cache-chains",
      "record": {
        "id": "research-zhero-nextjs-cache-chains",
        "source": "researcher",
        "sourceLabel": "zhero",
        "sourceType": "technique-research",
        "sourceUrl": "https://zhero-web-sec.github.io/research-and-things/nextjs-cache-and-chains-the-stale-elixir",
        "title": "Next.js, cache, and chains: the stale elixir",
        "program": "Next.js",
        "reporter": "Rachid Allam",
        "severityLabel": "Technique research",
        "severitySystem": "Publication type, not severity",
        "severityBasis": "not-severity",
        "disclosedAt": "2025-01-01",
        "vulnerabilityClass": "request-boundary",
        "publishedOutcome": "The author states related reports cumulatively reached six figures. No individual severity is inferred.",
        "hunterAngle": "Review framework cache keys, revalidation, and race windows as one state machine rather than independent bugs.",
        "reviewStatus": "canonical-source-reviewed"
      }
    },
    {
      "id": "report:hackerone-2794126",
      "url": "https://vulns.co/api/v1/reports/hackerone-2794126/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2794126",
      "record": {
        "id": "hackerone-2794126",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2794126",
        "sourceUrl": "https://hackerone.com/reports/2794126",
        "title": "CVE-2020-5902",
        "program": "AWS VDP",
        "programUrl": "https://hackerone.com/aws_vdp",
        "reporter": "perigou",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-12-24",
        "submittedAt": "2024-10-21",
        "weakness": "Using Components with Known Vulnerabilities",
        "vulnerabilityClass": "critical-path",
        "cves": [
          "CVE-2020-5902"
        ],
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2083771",
      "url": "https://vulns.co/api/v1/reports/hackerone-2083771/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2083771",
      "record": {
        "id": "hackerone-2083771",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2083771",
        "sourceUrl": "https://hackerone.com/reports/2083771",
        "title": "Remote Code Execution and AWS IAM Credentials Exfiltration in https://████████/",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "shuvam321",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-12-18",
        "submittedAt": "2023-07-25",
        "weakness": "Command Injection - Generic",
        "vulnerabilityClass": "injection",
        "summary": "The host https://██████/ had a vulnerability in the /jenkins/script directory that allowed users to execute system commands on the host. This could have led to the disclosure of AWS IAM credentials, which could have been used by an attacker to manage various AWS resources, create and delete resources, read and write data in AWS services, create and manage other IAM users and roles, access the AWS Management Console, and use the AWS Command Line Interface (CLI).",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2871792",
      "url": "https://vulns.co/api/v1/reports/hackerone-2871792/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2871792",
      "record": {
        "id": "hackerone-2871792",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2871792",
        "sourceUrl": "https://hackerone.com/reports/2871792",
        "title": "Buffer Overflow Vulnerability in strcpy() Leading to Remote Code Execution",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "lostnotfound123",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-12-02",
        "submittedAt": "2024-11-30",
        "weakness": "Classic Buffer Overflow",
        "vulnerabilityClass": "code-execution",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2756402",
      "url": "https://vulns.co/api/v1/reports/hackerone-2756402/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2756402",
      "record": {
        "id": "hackerone-2756402",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2756402",
        "sourceUrl": "https://hackerone.com/reports/2756402",
        "title": "█████████ when adding branches to your account",
        "program": "Mars",
        "programUrl": "https://hackerone.com/mars",
        "reporter": "kh4rish34v3n",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-11-26",
        "submittedAt": "2024-10-03",
        "weakness": "Insecure Direct Object Reference (IDOR)",
        "vulnerabilityClass": "access-control",
        "summary": "A vulnerability was identified in the branch addition functionality of the Royal Canin specialized channel website. The issue was classified as an Insecure Direct Object Reference (IDOR) vulnerability, which allowed unauthorized users to add branches to any account by manipulating the customer's routing number (RUT) in the request parameter.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2762119",
      "url": "https://vulns.co/api/v1/reports/hackerone-2762119/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2762119",
      "record": {
        "id": "hackerone-2762119",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2762119",
        "sourceUrl": "https://hackerone.com/reports/2762119",
        "title": "CVE-2017-9822 DotNetNuke Cookie Deserialization Remote Code Execution (RCE) on lonidoor.mtn.ci",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "odaysec",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-11-16",
        "submittedAt": "2024-10-06",
        "weakness": "Code Injection",
        "vulnerabilityClass": "injection",
        "cves": [
          "CVE-2017-9822"
        ],
        "summary": "The DotNetNuke (DNN) versions between 5.0.0 and 9.3.0 were affected by a deserialization vulnerability that could lead to remote code execution. The vulnerability was caused by the way DNN handled the `DNNPersonalization` cookie, which was used to store anonymous users' personalization options. The vulnerability was exploitable when the application was configured to handle 404 errors with its built-in error page.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2823554",
      "url": "https://vulns.co/api/v1/reports/hackerone-2823554/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2823554",
      "record": {
        "id": "hackerone-2823554",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2823554",
        "sourceUrl": "https://hackerone.com/reports/2823554",
        "title": "Buffer overflow in strcpy",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "rootgh0st",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-11-07",
        "submittedAt": "2024-11-06",
        "weakness": "Buffer Underflow",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2733190",
      "url": "https://vulns.co/api/v1/reports/hackerone-2733190/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2733190",
      "record": {
        "id": "hackerone-2733190",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2733190",
        "sourceUrl": "https://hackerone.com/reports/2733190",
        "title": "Overwrite any file of the web server",
        "program": "MOD Supply Chain VDP",
        "programUrl": "https://hackerone.com/mod_supply_chain_vdp",
        "reporter": "goedix",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-11-05",
        "submittedAt": "2024-09-21",
        "weakness": "File Manipulation",
        "vulnerabilityClass": "critical-path",
        "summary": "The web server was vulnerable to file overwrite due to a vulnerable module used to generate files. An attacker could have overwritten any file on the web server, including critical system files, by sending a specially crafted request.",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2748003",
      "url": "https://vulns.co/api/v1/reports/hackerone-2748003/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2748003",
      "record": {
        "id": "hackerone-2748003",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2748003",
        "sourceUrl": "https://hackerone.com/reports/2748003",
        "title": "Lack of rate limiting in https://███/PKI/PassReset.aspx leads to PII disclosure and potential account takeover",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "hypervis0r",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-10-25",
        "submittedAt": "2024-09-29",
        "weakness": "Information Exposure Through an Error Message",
        "vulnerabilityClass": "identity",
        "summary": "The password reset functionality of AFPC Secure allowed users to provide their Social Security Account Number (SSAN) and Mother's Maiden Name to reset their password. The issue was that the system informed the user if the SSAN was associated with an active PKI credential, leading to potential disclosure of personally identifiable information. Additionally, the lack of rate limiting allowed an attacker to brute force through a large number of SSANs.",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2742457",
      "url": "https://vulns.co/api/v1/reports/hackerone-2742457/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2742457",
      "record": {
        "id": "hackerone-2742457",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2742457",
        "sourceUrl": "https://hackerone.com/reports/2742457",
        "title": "CVE-2020-7961 RCE Liferay Portal Unauthenticated via https://████████/",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "exploitmsf",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-10-25",
        "submittedAt": "2024-09-26",
        "weakness": "OS Command Injection",
        "vulnerabilityClass": "injection",
        "cves": [
          "CVE-2020-7961"
        ],
        "summary": "CVE-2020-7961 was a remote code execution vulnerability in Liferay Portal. The vulnerability was exploited through the \"/api/jsonws/invoke\" endpoint, which allowed unauthenticated users to execute arbitrary commands on the server.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1541740",
      "url": "https://vulns.co/api/v1/reports/hackerone-1541740/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1541740",
      "record": {
        "id": "hackerone-1541740",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1541740",
        "sourceUrl": "https://hackerone.com/reports/1541740",
        "title": "Pull Any Automated Record Brief",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "badlifeguard",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-10-25",
        "submittedAt": "2022-04-14",
        "weakness": "Information Disclosure",
        "vulnerabilityClass": "data-exposure",
        "summary": "The vulnerability allows an authenticated user to request other soldiers' Automated Record Briefs (ARBs) or Officer Record Briefs (ORBs) by manipulating the URL. The URL contained an identifier that could be incrementally changed to access the records of other individuals. This vulnerability exposed personal information such as the last four digits of the Social Security number, date of birth, place of birth, clearance information, mailing address, and Defense Department ID number.",
        "hunterAngle": "Identify the intended audience and the narrowest unauthorized observer. Use controlled records, distinguish metadata from secret material, and quantify the repeatable exposure boundary.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2401648",
      "url": "https://vulns.co/api/v1/reports/hackerone-2401648/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2401648",
      "record": {
        "id": "hackerone-2401648",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2401648",
        "sourceUrl": "https://hackerone.com/reports/2401648",
        "title": "two aws access key and secret key and database username and password exposed",
        "program": "Mozilla",
        "programUrl": "https://hackerone.com/mozilla",
        "reporter": "ghaazy",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-10-18",
        "submittedAt": "2024-03-04",
        "weakness": "Information Disclosure",
        "vulnerabilityClass": "data-exposure",
        "summary": "A security vulnerability was identified in a Docker image hosted on Docker Hub. The image, associated with Mozilla's Common Voice project, was found to contain exposed AWS access keys, AWS secret keys, and database credentials. These sensitive credentials were discovered within the file /code/scripts/test/config.json of the Docker image. The images were deleted from Docker Hub, the credentials were rotated, and the AWS users associated with them were removed.",
        "hunterAngle": "Identify the intended audience and the narrowest unauthorized observer. Use controlled records, distinguish metadata from secret material, and quantify the repeatable exposure boundary.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2579939",
      "url": "https://vulns.co/api/v1/reports/hackerone-2579939/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2579939",
      "record": {
        "id": "hackerone-2579939",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2579939",
        "sourceUrl": "https://hackerone.com/reports/2579939",
        "title": "SAML Signature verification bypass allows logging into any user (with specific conditions)",
        "program": "GitHub",
        "programUrl": "https://hackerone.com/github",
        "reporter": "ahacker1",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-10-10",
        "submittedAt": "2024-06-27",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "cves": [
          "CVE-2024-6800"
        ],
        "summary": "The vulnerability allowed an attacker with direct network access to GitHub Enterprise Server to forge a SAML response and gain unauthorized access to the instance, including site administrator privileges, by exploiting a signature verification bypass. The vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was addressed in versions 3.13.3, 3.12.8, 3.11.14, and 3.10.16.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2588329",
      "url": "https://vulns.co/api/v1/reports/hackerone-2588329/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2588329",
      "record": {
        "id": "hackerone-2588329",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2588329",
        "sourceUrl": "https://hackerone.com/reports/2588329",
        "title": "Change phone number OTP flaw leads to any phone number takeover",
        "program": "inDrive",
        "programUrl": "https://hackerone.com/indrive",
        "reporter": "polem4rch",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-10-09",
        "submittedAt": "2024-07-07",
        "weakness": "Business Logic Errors",
        "vulnerabilityClass": "critical-path",
        "bounty": {
          "value": 2000,
          "currency": "USD"
        },
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2182202",
      "url": "https://vulns.co/api/v1/reports/hackerone-2182202/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2182202",
      "record": {
        "id": "hackerone-2182202",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2182202",
        "sourceUrl": "https://hackerone.com/reports/2182202",
        "title": "Remote code execution [CVE-2023-36845]",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "m4lc0lmx",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-10-09",
        "submittedAt": "2023-09-26",
        "vulnerabilityClass": "code-execution",
        "cves": [
          "CVE-2023-36845"
        ],
        "summary": "A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series was discovered. The vulnerability allowed an unauthenticated, network-based attacker to control certain, important environment variables.",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2039384",
      "url": "https://vulns.co/api/v1/reports/hackerone-2039384/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2039384",
      "record": {
        "id": "hackerone-2039384",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2039384",
        "sourceUrl": "https://hackerone.com/reports/2039384",
        "title": "Reflected XSS in https://nin.mtn.ng/nin/success?message=lol&nin=<VULNERABLE>",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "hazemhussien99",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-10-05",
        "submittedAt": "2023-06-26",
        "weakness": "Cross-site Scripting (XSS) - Reflected",
        "vulnerabilityClass": "browser-injection",
        "summary": "The reflected XSS vulnerability was found in the 'nin' parameter of the 'https://nin.mtn.ng/nin/success' endpoint. Successful exploitation allowed an attacker to execute arbitrary JavaScript in the victim's browser.",
        "hunterAngle": "Locate the exact browser sink and encoding context. Prove execution with a harmless marker, then test whether privilege, origin, or persistence changes the impact.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1773609",
      "url": "https://vulns.co/api/v1/reports/hackerone-1773609/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1773609",
      "record": {
        "id": "hackerone-1773609",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1773609",
        "sourceUrl": "https://hackerone.com/reports/1773609",
        "title": "IDOR at mtnmobad.mtnbusiness.com.ng leads to PII leakage.",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "hazemhussien99",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-10-05",
        "submittedAt": "2022-11-14",
        "weakness": "Insecure Direct Object Reference (IDOR)",
        "vulnerabilityClass": "access-control",
        "summary": "The IDOR vulnerability at mtnmobad.mtnbusiness.com.ng allowed the personal information of users, such as their phone numbers and account details, to be accessed by an attacker who knew the user's email address. The vulnerable request was a POST to the /app/getUserNotes endpoint, which accepted the user's email in the request body and returned the sensitive personal information.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1714638",
      "url": "https://vulns.co/api/v1/reports/hackerone-1714638/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1714638",
      "record": {
        "id": "hackerone-1714638",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1714638",
        "sourceUrl": "https://hackerone.com/reports/1714638",
        "title": "IDOR Leads To User Profile Modification https://mtnmobad.mtnbusiness.com.ng/app/updateUser",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "reachaxis",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-09-18",
        "submittedAt": "2022-09-27",
        "weakness": "Incorrect Authorization",
        "vulnerabilityClass": "access-control",
        "summary": "A vulnerability in the web application allowed authenticated users to modify the profile information of any other user without proper authorization checks. The issue was caused by the lack of sufficient authorization controls when updating user profiles through the `/app/updateUser` endpoint.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1709881",
      "url": "https://vulns.co/api/v1/reports/hackerone-1709881/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1709881",
      "record": {
        "id": "hackerone-1709881",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1709881",
        "sourceUrl": "https://hackerone.com/reports/1709881",
        "title": "Authentication Bypass Leads To Complete Account TakeveOver on ██████████",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "reachaxis",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-09-14",
        "submittedAt": "2022-09-23",
        "weakness": "Authentication Bypass Using an Alternate Path or Channel",
        "vulnerabilityClass": "identity",
        "summary": "The application's backend logic placed too much trust on the login information submitted by the user, which allowed a remote attacker to bypass authentication and perform account takeover.",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2375666",
      "url": "https://vulns.co/api/v1/reports/hackerone-2375666/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2375666",
      "record": {
        "id": "hackerone-2375666",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2375666",
        "sourceUrl": "https://hackerone.com/reports/2375666",
        "title": "CVE-2018-0296 Cisco ASA Denial of Service & Path Traversal vulnerable on [mtn.co.ug]",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "deb0con",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-08-30",
        "submittedAt": "2024-02-15",
        "weakness": "Path Traversal: '.../...//'",
        "vulnerabilityClass": "file-boundary",
        "cves": [
          "CVE-2018-0296"
        ],
        "summary": "The Cisco Adaptive Security Appliance (ASA) was affected by a vulnerability in its web interface that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service condition. In certain software releases, the vulnerability also could have allowed the attacker to view sensitive system information without authentication by using directory traversal techniques. The vulnerability was due to improper input validation of the HTTP URL. The vulnerability affected Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software running on various Cisco products.",
        "hunterAngle": "Trace filename, path, content type, storage, and retrieval as separate controls. Use inert files and confirm the smallest boundary violation before testing execution paths.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1459714",
      "url": "https://vulns.co/api/v1/reports/hackerone-1459714/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1459714",
      "record": {
        "id": "hackerone-1459714",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1459714",
        "sourceUrl": "https://hackerone.com/reports/1459714",
        "title": "[CVE-2021-44228] Arbitrary Code Execution on ng01-cloud.acronis.com",
        "program": "Acronis",
        "programUrl": "https://hackerone.com/acronis",
        "reporter": "mikkocarreon",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-08-28",
        "submittedAt": "2022-01-25",
        "vulnerabilityClass": "code-execution",
        "cves": [
          "CVE-2021-44228"
        ],
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1430622",
      "url": "https://vulns.co/api/v1/reports/hackerone-1430622/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1430622",
      "record": {
        "id": "hackerone-1430622",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1430622",
        "sourceUrl": "https://hackerone.com/reports/1430622",
        "title": "[forum.acronis.com] JNDI Code Injection due an outdated log4j component",
        "program": "Acronis",
        "programUrl": "https://hackerone.com/acronis",
        "reporter": "godiego",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-08-28",
        "submittedAt": "2021-12-19",
        "weakness": "OS Command Injection",
        "vulnerabilityClass": "injection",
        "cves": [
          "CVE-2021-44228"
        ],
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1425565",
      "url": "https://vulns.co/api/v1/reports/hackerone-1425565/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1425565",
      "record": {
        "id": "hackerone-1425565",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1425565",
        "sourceUrl": "https://hackerone.com/reports/1425565",
        "title": "Remote code injection in Log4j on https://mymtn.mtncongo.net - CVE-2021-44228",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "renzi",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-08-24",
        "submittedAt": "2021-12-14",
        "weakness": "OS Command Injection",
        "vulnerabilityClass": "injection",
        "cves": [
          "CVE-2021-44228"
        ],
        "summary": "The website https://mymtn.mtncongo.net was vulnerable to remote code injection due to the CVE-2021-44228 vulnerability in the Log4j library. This critical vulnerability allowed for remote command execution.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1425563",
      "url": "https://vulns.co/api/v1/reports/hackerone-1425563/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1425563",
      "record": {
        "id": "hackerone-1425563",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1425563",
        "sourceUrl": "https://hackerone.com/reports/1425563",
        "title": "Remote code injection in Log4j on http://mtn1app.mtncameroon.net - CVE-2021-44228",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "renzi",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-08-24",
        "submittedAt": "2021-12-14",
        "weakness": "OS Command Injection",
        "vulnerabilityClass": "injection",
        "cves": [
          "CVE-2021-44228"
        ],
        "summary": "The vulnerability CVE-2021-44228, a remote code injection flaw in Log4j, was discovered on the website http://mtn1app.mtncameroon.net. The vulnerability was confirmed to be present on the ports 8080 and 8443 of the website. The issue was demonstrated by retrieving the hostname of the affected machine using a nuclei script.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2542372",
      "url": "https://vulns.co/api/v1/reports/hackerone-2542372/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2542372",
      "record": {
        "id": "hackerone-2542372",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2542372",
        "sourceUrl": "https://hackerone.com/reports/2542372",
        "title": "FULL ACCOUNT TAKEOVER",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "impozzible",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-08-17",
        "submittedAt": "2024-06-08",
        "vulnerabilityClass": "identity",
        "summary": "The selfservice portal at https://mymtn.com.ng/ allowed an attacker to take over any Nigerian MTN phone number. The attacker was able to access the account holder's personal information, such as date of birth and full name. The attacker also had the ability to use any available airtime on the account.",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2633988",
      "url": "https://vulns.co/api/v1/reports/hackerone-2633988/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2633988",
      "record": {
        "id": "hackerone-2633988",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2633988",
        "sourceUrl": "https://hackerone.com/reports/2633988",
        "title": "DoD workstation exposed to internet via TinyPilot KVM with no authentication",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "socpuppet",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-08-16",
        "submittedAt": "2024-08-01",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "The DoD workstation was exposed to the internet via a TinyPilot KVM device without any authentication. The TinyPilot KVM device was connected to the workstation and allowed remote access to the system over the internet.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-501081",
      "url": "https://vulns.co/api/v1/reports/hackerone-501081/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-501081",
      "record": {
        "id": "hackerone-501081",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "501081",
        "sourceUrl": "https://hackerone.com/reports/501081",
        "title": "Guest Privilege Escalation to admin group",
        "program": "Rocket.Chat",
        "programUrl": "https://hackerone.com/rocket_chat",
        "reporter": "gronke",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-08-10",
        "submittedAt": "2019-02-25",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "The vulnerability allowed a guest user to escalate privileges to the admin group. The guest user first added themselves to the bot group, which had the \"manage-own-integrations\" permission. Using this, the user created a malicious integration script that added the user to the admin group. The vulnerability existed due to improper validation in the \"insertOrUpdateUser\" method, which did not properly check the user's permissions when modifying their groups.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-219957",
      "url": "https://vulns.co/api/v1/reports/hackerone-219957/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-219957",
      "record": {
        "id": "hackerone-219957",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "219957",
        "sourceUrl": "https://hackerone.com/reports/219957",
        "title": "XSS via /api/v1/chat.postMessage",
        "program": "Rocket.Chat",
        "programUrl": "https://hackerone.com/rocket_chat",
        "reporter": "gronke",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-08-10",
        "submittedAt": "2017-04-10",
        "weakness": "Cross-site Scripting (XSS) - Stored",
        "vulnerabilityClass": "browser-injection",
        "summary": "The victim could craft a custom message using the REST API that, once seen by the observer, executed arbitrary code in the context of the client user. The vulnerability was present in the attachment fields, where the first field's value could be used to inject HTML tags.",
        "hunterAngle": "Locate the exact browser sink and encoding context. Prove execution with a harmless marker, then test whether privilege, origin, or persistence changes the impact.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1447619",
      "url": "https://vulns.co/api/v1/reports/hackerone-1447619/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1447619",
      "record": {
        "id": "hackerone-1447619",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1447619",
        "sourceUrl": "https://hackerone.com/reports/1447619",
        "title": "Authentication Bypass in login-token Authentication Method",
        "program": "Rocket.Chat",
        "programUrl": "https://hackerone.com/rocket_chat",
        "reporter": "gronke",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-08-10",
        "submittedAt": "2022-01-12",
        "weakness": "Improper Authentication - Generic",
        "vulnerabilityClass": "identity",
        "summary": "The Rocket.Chat application contained a vulnerability in the login-token authentication method that allowed for authentication bypass. Improper input data validation in the login-token authentication handler permitted the use of crafted data to obtain a valid authToken, granting administrative access to the application.",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-949361",
      "url": "https://vulns.co/api/v1/reports/hackerone-949361/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-949361",
      "record": {
        "id": "hackerone-949361",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "949361",
        "sourceUrl": "https://hackerone.com/reports/949361",
        "title": "Shell command injection in https://partner.steamgames.com/admin/game/publish/ via screenshot URL",
        "program": "Valve",
        "programUrl": "https://hackerone.com/valve",
        "reporter": "njbooher3",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-07-30",
        "submittedAt": "2020-08-01",
        "weakness": "OS Command Injection",
        "vulnerabilityClass": "injection",
        "summary": "Shell command injection in https://partner.steamgames.com/admin/game/publish/ via screenshot URL The vulnerability allowed insufficient validation of parameters, which permitted the injection of shell metacharacters into values used to construct a Bash command.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-926169",
      "url": "https://vulns.co/api/v1/reports/hackerone-926169/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-926169",
      "record": {
        "id": "hackerone-926169",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "926169",
        "sourceUrl": "https://hackerone.com/reports/926169",
        "title": "Shell command injection in https://partner.steamgames.com/bundles/savestore/ via overwriting asset_path_identifier",
        "program": "Valve",
        "programUrl": "https://hackerone.com/valve",
        "reporter": "njbooher3",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-07-30",
        "submittedAt": "2020-07-17",
        "weakness": "OS Command Injection",
        "vulnerabilityClass": "injection",
        "summary": "Shell command injection in https://partner.steamgames.com/bundles/savestore/ via overwriting asset_path_identifier. Insufficient validation of parameters allowed injecting shell metacharacters into values used to construct a Bash command.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-840243",
      "url": "https://vulns.co/api/v1/reports/hackerone-840243/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-840243",
      "record": {
        "id": "hackerone-840243",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "840243",
        "sourceUrl": "https://hackerone.com/reports/840243",
        "title": "Shell command injection in https://partner.steamgames.com/apps/communityitems/ via file extension of item_image_small and item_image_large",
        "program": "Valve",
        "programUrl": "https://hackerone.com/valve",
        "reporter": "njbooher3",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-07-30",
        "submittedAt": "2020-04-04",
        "weakness": "Command Injection - Generic",
        "vulnerabilityClass": "injection",
        "summary": "Shell command injection in https://partner.steamgames.com/apps/communityitems/ via file extension of item_image_small and item_image_large. Shell injection was achieved on a publishing gateway through metacharacter injection in an item-upload path.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-690349",
      "url": "https://vulns.co/api/v1/reports/hackerone-690349/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-690349",
      "record": {
        "id": "hackerone-690349",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "690349",
        "sourceUrl": "https://hackerone.com/reports/690349",
        "title": "SQL injection in /errors/viewbuild/",
        "program": "Valve",
        "programUrl": "https://hackerone.com/valve",
        "reporter": "njbooher3",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-07-30",
        "submittedAt": "2019-09-08",
        "weakness": "SQL Injection",
        "vulnerabilityClass": "injection",
        "summary": "A SQL injection vulnerability was discovered in a partner-facing tool that allowed queries against a legacy backing store.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-652649",
      "url": "https://vulns.co/api/v1/reports/hackerone-652649/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-652649",
      "record": {
        "id": "hackerone-652649",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "652649",
        "sourceUrl": "https://hackerone.com/reports/652649",
        "title": "WG call injection in /economy/contextcommand",
        "program": "Valve",
        "programUrl": "https://hackerone.com/valve",
        "reporter": "njbooher3",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-07-30",
        "submittedAt": "2019-07-22",
        "weakness": "Command Injection - Generic",
        "vulnerabilityClass": "injection",
        "summary": "The vulnerability involved insufficient parameter validation in context-specific commands to a web-facing gateway. This allowed some economy queries to be executed outside the actual requesters' capability by confusing the type system. Bypasses for initial fixes were also provided.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-518348",
      "url": "https://vulns.co/api/v1/reports/hackerone-518348/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-518348",
      "record": {
        "id": "hackerone-518348",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "518348",
        "sourceUrl": "https://hackerone.com/reports/518348",
        "title": "RCE on partner.steampowered.com",
        "program": "Valve",
        "programUrl": "https://hackerone.com/valve",
        "reporter": "njbooher3",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-07-30",
        "submittedAt": "2019-03-28",
        "weakness": "Command Injection - Generic",
        "vulnerabilityClass": "injection",
        "summary": "The vulnerability on partner.steampowered.com involved insufficient validation of parameters, which allowed an attacker to specify the name of a PHP function to call with specific parameter types. This could be exploited to call the assert function, which at the time invoked eval, enabling arbitrary code execution.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2552243",
      "url": "https://vulns.co/api/v1/reports/hackerone-2552243/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2552243",
      "record": {
        "id": "hackerone-2552243",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2552243",
        "sourceUrl": "https://hackerone.com/reports/2552243",
        "title": "Subdomain takeover ██████",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "martinvw",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-07-26",
        "submittedAt": "2024-06-14",
        "weakness": "Violation of Secure Design Principles",
        "vulnerabilityClass": "critical-path",
        "summary": "The subdomain `█████` was found to be pointing to `open-elb-prod-277276106.us-east-1.elb-amazonaws.com.`, and the domain `elb-amazonaws.com` was available for registration. This vulnerability could have been exploited to host unwanted content, receive email, and potentially execute cross-site scripting attacks.",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1991290",
      "url": "https://vulns.co/api/v1/reports/hackerone-1991290/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1991290",
      "record": {
        "id": "hackerone-1991290",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1991290",
        "sourceUrl": "https://hackerone.com/reports/1991290",
        "title": "Endpoint Redirects to Admin Page and Provides Admin role",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "bulldawg",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-07-19",
        "submittedAt": "2023-05-18",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "The web application running on Oracle Apex Express platform was found to have an endpoint that redirected users to the admin page and provided them with admin privileges, bypassing access control restrictions. The vulnerability was discovered by navigating to a specific page within the application.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1991214",
      "url": "https://vulns.co/api/v1/reports/hackerone-1991214/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1991214",
      "record": {
        "id": "hackerone-1991214",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1991214",
        "sourceUrl": "https://hackerone.com/reports/1991214",
        "title": "Automatic Admin Access",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "bulldawg",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-07-19",
        "submittedAt": "2023-05-17",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "The automatic administrative access vulnerability allowed a user to access the application with full administrative privileges, including the ability to create submissions, manage users, and access sensitive data. The vulnerability impacted the integrity, confidentiality, and availability of the application.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2443228",
      "url": "https://vulns.co/api/v1/reports/hackerone-2443228/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2443228",
      "record": {
        "id": "hackerone-2443228",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2443228",
        "sourceUrl": "https://hackerone.com/reports/2443228",
        "title": "Account Takeover via Authentication Bypass in TikTok Account Recovery",
        "program": "TikTok",
        "programUrl": "https://hackerone.com/tiktok",
        "reporter": "fl4w",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-07-13",
        "submittedAt": "2024-04-01",
        "weakness": "Authentication Bypass Using an Alternate Path or Channel",
        "vulnerabilityClass": "identity",
        "bounty": {
          "value": 12000,
          "currency": "USD"
        },
        "summary": "An improper authentication mechanism in TikTok's account recovery process was identified. The vulnerability was reported and has been completely fixed. There was no evidence of exploitation.",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2501984",
      "url": "https://vulns.co/api/v1/reports/hackerone-2501984/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2501984",
      "record": {
        "id": "hackerone-2501984",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2501984",
        "sourceUrl": "https://hackerone.com/reports/2501984",
        "title": "Bypassing the victim's phone number OTP in the account recovery process on the https://hackerone.com/settings/auth/setup_account_recovery",
        "program": "HackerOne",
        "programUrl": "https://hackerone.com/security",
        "reporter": "the-white-evil",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-07-11",
        "submittedAt": "2024-05-12",
        "weakness": "Improper Authentication - Generic",
        "vulnerabilityClass": "identity",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-684836",
      "url": "https://vulns.co/api/v1/reports/hackerone-684836/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-684836",
      "record": {
        "id": "hackerone-684836",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "684836",
        "sourceUrl": "https://hackerone.com/reports/684836",
        "title": "Local File Disclosure on the █████ (https://████████.edu/) leads to the full source code disclosure and credentials leak",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "sp1d3rs",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-06-27",
        "submittedAt": "2019-08-30",
        "weakness": "Insecure Storage of Sensitive Information",
        "vulnerabilityClass": "code-execution",
        "summary": "A local file disclosure vulnerability was discovered on the █████ website (https://████████.edu/). The vulnerability allowed an attacker to download the website's configuration file, which exposed the database credentials. Additionally, the source code for certain server-side resources was also accessible. The vulnerability led to the disclosure of sensitive information, including the source code and database credentials.",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2499178",
      "url": "https://vulns.co/api/v1/reports/hackerone-2499178/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2499178",
      "record": {
        "id": "hackerone-2499178",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2499178",
        "sourceUrl": "https://hackerone.com/reports/2499178",
        "title": "Subdomain takeover ████████.mil",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "martinvw",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-06-27",
        "submittedAt": "2024-05-10",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "The subdomain ██████.mil was found to be pointing to a domain that is currently available for registration. This indicates a potential subdomain takeover vulnerability. The domain ████ was found to be unregistered and could have been used by an attacker to host unwanted or malicious content under the affected subdomain.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2515808",
      "url": "https://vulns.co/api/v1/reports/hackerone-2515808/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2515808",
      "record": {
        "id": "hackerone-2515808",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2515808",
        "sourceUrl": "https://hackerone.com/reports/2515808",
        "title": "[Meetup][World ID][OIDC] Insufficient Filtering of \"state\" Parameter in Response Mode form_post leads to XSS and ATO",
        "program": "Tools for Humanity",
        "programUrl": "https://hackerone.com/toolsforhumanity",
        "reporter": "lauritz",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-06-19",
        "submittedAt": "2024-05-22",
        "weakness": "Cross-Site Scripting (XSS)",
        "vulnerabilityClass": "browser-injection",
        "summary": "A lack of proper validation in the state parameter of the World ID OIDC authentication logic allowed the injection of HTML characters into the response body when using form_post as the OIDC response mode. This vulnerability was mitigated by the Content Security Policy (CSP).",
        "hunterAngle": "Locate the exact browser sink and encoding context. Prove execution with a harmless marker, then test whether privilege, origin, or persistence changes the impact.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-728614",
      "url": "https://vulns.co/api/v1/reports/hackerone-728614/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-728614",
      "record": {
        "id": "hackerone-728614",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "728614",
        "sourceUrl": "https://hackerone.com/reports/728614",
        "title": "[HTAF4-213] [Pre-submission] Unsafe AMF deserialization (CVE-2017-5641) in Apache Flex BlazeDS at the https://www.███████/daip/messagebroker/amf",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "sp1d3rs",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-06-18",
        "submittedAt": "2019-11-04",
        "weakness": "Deserialization of Untrusted Data",
        "vulnerabilityClass": "code-execution",
        "cves": [
          "CVE-2017-5641"
        ],
        "summary": "The vulnerability was an unsafe AMF (Action Message Format) deserialization issue in Apache Flex BlazeDS, affecting the `/daip/messagebroker/amf` endpoint. Successful exploitation could allow an attacker to trigger a DNS lookup by sending a crafted AMF payload. The vulnerability was identified and reported prior to submission.",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2188240",
      "url": "https://vulns.co/api/v1/reports/hackerone-2188240/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2188240",
      "record": {
        "id": "hackerone-2188240",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2188240",
        "sourceUrl": "https://hackerone.com/reports/2188240",
        "title": "Subdomain Takeover via Host Header Injection on www.█████",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "ezequielpuig",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-06-18",
        "submittedAt": "2023-10-01",
        "weakness": "Violation of Secure Design Principles",
        "vulnerabilityClass": "injection",
        "summary": "The vulnerability was a subdomain takeover due to a CNAME record pointing to an unclaimed domain. This allowed malicious individuals to potentially take control of the affected subdomain and use it for malicious purposes.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2315420",
      "url": "https://vulns.co/api/v1/reports/hackerone-2315420/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2315420",
      "record": {
        "id": "hackerone-2315420",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2315420",
        "sourceUrl": "https://hackerone.com/reports/2315420",
        "title": "Email OTP/2FA Bypass",
        "program": "Drugs.com",
        "programUrl": "https://hackerone.com/drugs_com",
        "reporter": "akhan8041",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-06-16",
        "submittedAt": "2024-01-14",
        "weakness": "Improper Authentication - Generic",
        "vulnerabilityClass": "identity",
        "summary": "The application had a 2FA functionality by email OTP. The vulnerability allowed bypassing the 2FA by deleting the \"bb_refresh\" cookie during the authentication process. This enabled successful login without the required 2FA.",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2487889",
      "url": "https://vulns.co/api/v1/reports/hackerone-2487889/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2487889",
      "record": {
        "id": "hackerone-2487889",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2487889",
        "sourceUrl": "https://hackerone.com/reports/2487889",
        "title": "Insecure Direct Object Reference (IDOR) Allows Viewing Private Report Details via /bugs.json Endpoint",
        "program": "HackerOne",
        "programUrl": "https://hackerone.com/security",
        "reporter": "bate5a",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-05-23",
        "submittedAt": "2024-05-02",
        "weakness": "Insecure Direct Object Reference (IDOR)",
        "vulnerabilityClass": "access-control",
        "summary": "The Insecure Direct Object Reference (IDOR) vulnerability allowed viewing private report details through the /bugs.json endpoint. Any private reports could be accessed by sending a POST request to the endpoint with the organization ID and a single-digit text query. This gave access to sensitive information such as report titles, URLs, IDs, states, substates, severity ratings, submission details, and reporter names.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2493548",
      "url": "https://vulns.co/api/v1/reports/hackerone-2493548/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2493548",
      "record": {
        "id": "hackerone-2493548",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2493548",
        "sourceUrl": "https://hackerone.com/reports/2493548",
        "title": "Incorrect Type Conversion in interpreting IPv4-mapped IPv6 addresses and below `curl` results in indeterminate SSRF vulnerabilities.",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "z3r0yu",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-05-08",
        "submittedAt": "2024-05-07",
        "weakness": "Type Confusion",
        "vulnerabilityClass": "ssrf",
        "cves": [
          "CVE-2023-24329",
          "CVE-2024-22243"
        ],
        "hunterAngle": "Map URL parsing, redirects, DNS resolution, and egress as separate decisions. Use an owned callback and compare it with a non-routable control without probing unrelated internal services.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2456603",
      "url": "https://vulns.co/api/v1/reports/hackerone-2456603/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2456603",
      "record": {
        "id": "hackerone-2456603",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2456603",
        "sourceUrl": "https://hackerone.com/reports/2456603",
        "title": "Insecure Direct Object Reference Protection bypass by changing HTTP method in IBM Your Learning endpoint.",
        "program": "IBM",
        "programUrl": "https://hackerone.com/ibm",
        "reporter": "suryahss",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-05-01",
        "submittedAt": "2024-04-09",
        "weakness": "Insecure Direct Object Reference (IDOR)",
        "vulnerabilityClass": "access-control",
        "summary": "The Insecure Direct Object Reference vulnerability in the IBM Your Learning endpoint was reported, analyzed, and remediated. The vulnerability allowed bypassing the protection by changing the HTTP method.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2442008",
      "url": "https://vulns.co/api/v1/reports/hackerone-2442008/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2442008",
      "record": {
        "id": "hackerone-2442008",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2442008",
        "sourceUrl": "https://hackerone.com/reports/2442008",
        "title": "Attachment disclosure via summary report",
        "program": "HackerOne",
        "programUrl": "https://hackerone.com/security",
        "reporter": "xklepxn",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-04-29",
        "submittedAt": "2024-03-30",
        "weakness": "Insecure Direct Object Reference (IDOR)",
        "vulnerabilityClass": "access-control",
        "summary": "A critical vulnerability was discovered in the HackerOne platform that allowed an attacker to gain unauthorized access to attachments belonging to other users through the report summary editing functionality. By manipulating attachment IDs in the request, an attacker could view sensitive files that should have been restricted. The core issue was an Insecure Direct Object Reference (IDOR) vulnerability where attachment access was not properly validated across user accounts when editing summary reports. This posed a serious risk to the confidentiality of user data.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2467999",
      "url": "https://vulns.co/api/v1/reports/hackerone-2467999/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2467999",
      "record": {
        "id": "hackerone-2467999",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2467999",
        "sourceUrl": "https://hackerone.com/reports/2467999",
        "title": "Jira Credential Disclosure within Mozilla Slack",
        "program": "Mozilla",
        "programUrl": "https://hackerone.com/mozilla",
        "reporter": "griffinf",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-04-23",
        "submittedAt": "2024-04-17",
        "weakness": "Information Disclosure",
        "vulnerabilityClass": "data-exposure",
        "bounty": {
          "value": 1000,
          "currency": "USD"
        },
        "summary": "The Jira admin API keys were disclosed within a Mozilla Slack channel by a staff member. The exposed credentials allowed for the verification of the user's elevated privileges, including being a Jira Administrator, Administrator, and Jira Service Desk user.",
        "hunterAngle": "Identify the intended audience and the narrowest unauthorized observer. Use controlled records, distinguish metadata from secret material, and quantify the repeatable exposure boundary.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2404415",
      "url": "https://vulns.co/api/v1/reports/hackerone-2404415/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2404415",
      "record": {
        "id": "hackerone-2404415",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2404415",
        "sourceUrl": "https://hackerone.com/reports/2404415",
        "title": "View any user email using the Team's audit log section",
        "program": "HackerOne",
        "programUrl": "https://hackerone.com/security",
        "reporter": "0v3rw4tch",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-03-26",
        "submittedAt": "2024-03-06",
        "weakness": "Information Disclosure",
        "vulnerabilityClass": "data-exposure",
        "hunterAngle": "Identify the intended audience and the narrowest unauthorized observer. Use controlled records, distinguish metadata from secret material, and quantify the repeatable exposure boundary.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2382120",
      "url": "https://vulns.co/api/v1/reports/hackerone-2382120/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2382120",
      "record": {
        "id": "hackerone-2382120",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2382120",
        "sourceUrl": "https://hackerone.com/reports/2382120",
        "title": "Creation of bounties through Customer API leads to private email disclosure",
        "program": "HackerOne",
        "programUrl": "https://hackerone.com/security",
        "reporter": "0v3rw4tch",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-03-26",
        "submittedAt": "2024-02-20",
        "weakness": "Information Disclosure",
        "vulnerabilityClass": "data-exposure",
        "summary": "The creation of bounties through the Customer API led to the disclosure of private email addresses. The vulnerability was demonstrated by using both the API and GraphQL requests to award a program bounty to a user, which then exposed the email address of that user in the response.",
        "hunterAngle": "Identify the intended audience and the narrowest unauthorized observer. Use controlled records, distinguish metadata from secret material, and quantify the repeatable exposure boundary.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2354136",
      "url": "https://vulns.co/api/v1/reports/hackerone-2354136/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2354136",
      "record": {
        "id": "hackerone-2354136",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2354136",
        "sourceUrl": "https://hackerone.com/reports/2354136",
        "title": "Attacker can Add itself as admin user and can also change privileges of Existing Users [█████████]",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "dishant_singh",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-03-22",
        "submittedAt": "2024-02-04",
        "weakness": "Improper Authentication - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "The website had a directory that lacked authentication, allowing an attacker to add a new admin user and change the privileges of existing users without any authentication.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2312609",
      "url": "https://vulns.co/api/v1/reports/hackerone-2312609/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2312609",
      "record": {
        "id": "hackerone-2312609",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2312609",
        "sourceUrl": "https://hackerone.com/reports/2312609",
        "title": "Full Access to sonarQube and Docker",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "micro01",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-03-22",
        "submittedAt": "2024-01-11",
        "weakness": "Information Disclosure",
        "vulnerabilityClass": "data-exposure",
        "summary": "The vulnerability involved the exposure of sensitive credentials and IP addresses in a JavaScript file. The researcher gained access to the organization's Hub Docker account and Sonar projects, allowing them to identify and assess the issue. The vulnerability was caused by a JavaScript file within the application that contained hard-coded sensitive credentials, such as usernames and passwords, as well as IP addresses associated with the infrastructure.",
        "hunterAngle": "Identify the intended audience and the narrowest unauthorized observer. Use controlled records, distinguish metadata from secret material, and quantify the repeatable exposure boundary.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2294930",
      "url": "https://vulns.co/api/v1/reports/hackerone-2294930/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2294930",
      "record": {
        "id": "hackerone-2294930",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2294930",
        "sourceUrl": "https://hackerone.com/reports/2294930",
        "title": "███ leaking PII of tour visitors (names, email addresses, phone numbers) via misconfigured record permissions",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "oxylis",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-03-22",
        "submittedAt": "2023-12-22",
        "weakness": "Cleartext Storage of Sensitive Information",
        "vulnerabilityClass": "access-control",
        "summary": "The ████████ portal was found to be leaking sensitive personal information, including full names, email addresses, and phone numbers of its users. The issue was caused by a misconfiguration that allowed registered users to access records of other users, potentially exposing the data of hundreds of thousands of individuals.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1770858",
      "url": "https://vulns.co/api/v1/reports/hackerone-1770858/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1770858",
      "record": {
        "id": "hackerone-1770858",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1770858",
        "sourceUrl": "https://hackerone.com/reports/1770858",
        "title": "IDOR vulnerability reveals additional information",
        "program": "Semrush",
        "programUrl": "https://hackerone.com/semrush",
        "reporter": "a_d_a_m",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-03-07",
        "submittedAt": "2022-11-11",
        "weakness": "Insecure Direct Object Reference (IDOR)",
        "vulnerabilityClass": "access-control",
        "summary": "An issue was identified in the Content Outline Builder product. Changing a user ID in a GraphQL request could reveal additional information about users. A subsequent internal review revealed no evidence of exploitation by unauthorized parties.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2212950",
      "url": "https://vulns.co/api/v1/reports/hackerone-2212950/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2212950",
      "record": {
        "id": "hackerone-2212950",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2212950",
        "sourceUrl": "https://hackerone.com/reports/2212950",
        "title": "Stored XSS on LinkedIn App via iframe tag in Article",
        "program": "LinkedIn",
        "programUrl": "https://hackerone.com/linkedin",
        "reporter": "bbdc71479bfeb4ba1cecaa5333f46",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-02-28",
        "submittedAt": "2023-10-17",
        "weakness": "Cross-site Scripting (XSS) - Stored",
        "vulnerabilityClass": "browser-injection",
        "summary": "A stored XSS vulnerability was reported in the LinkedIn Article feature, where a malicious JavaScript payload could be embedded in the URL field of an iframe. When such an article was published and accessed on the LinkedIn Mobile App, the malicious JavaScript was executed in the victim's context. The issue was resolved, and a bounty was paid to the researcher.",
        "hunterAngle": "Locate the exact browser sink and encoding context. Prove execution with a harmless marker, then test whether privilege, origin, or persistence changes the impact.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2357778",
      "url": "https://vulns.co/api/v1/reports/hackerone-2357778/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2357778",
      "record": {
        "id": "hackerone-2357778",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2357778",
        "sourceUrl": "https://hackerone.com/reports/2357778",
        "title": "Unrestricted File Upload at ██████████",
        "program": "Mars",
        "programUrl": "https://hackerone.com/mars",
        "reporter": "xplo1t",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-02-19",
        "submittedAt": "2024-02-07",
        "weakness": "Unrestricted Upload of File with Dangerous Type",
        "vulnerabilityClass": "file-boundary",
        "summary": "The endpoint \"████████\" enabled unrestricted file uploads, allowing anyone to upload any type of file without registration.",
        "hunterAngle": "Trace filename, path, content type, storage, and retrieval as separate controls. Use inert files and confirm the smallest boundary violation before testing execution paths.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1622432",
      "url": "https://vulns.co/api/v1/reports/hackerone-1622432/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1622432",
      "record": {
        "id": "hackerone-1622432",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1622432",
        "sourceUrl": "https://hackerone.com/reports/1622432",
        "title": "[SSRF] my.stripo.email via the setup-wizard parameter",
        "program": "Stripo Inc",
        "programUrl": "https://hackerone.com/stripo",
        "reporter": "deb0con",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-02-15",
        "submittedAt": "2022-07-01",
        "weakness": "Server-Side Request Forgery (SSRF)",
        "vulnerabilityClass": "ssrf",
        "summary": "A vulnerability in the setup wizard allowed SSRF. The issue has been resolved.",
        "hunterAngle": "Map URL parsing, redirects, DNS resolution, and egress as separate decisions. Use an owned callback and compare it with a non-routable control without probing unrelated internal services.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2266081",
      "url": "https://vulns.co/api/v1/reports/hackerone-2266081/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2266081",
      "record": {
        "id": "hackerone-2266081",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2266081",
        "sourceUrl": "https://hackerone.com/reports/2266081",
        "title": "Blind SQL Injection on █████ via URI Path",
        "program": "Mars",
        "programUrl": "https://hackerone.com/mars",
        "reporter": "stuux",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-02-14",
        "submittedAt": "2023-11-28",
        "weakness": "SQL Injection",
        "vulnerabilityClass": "injection",
        "summary": "The vulnerability involved a time-based SQL injection attack on the target system via the URI path. The attack capitalized on vulnerabilities in the application's interactions with the database, allowing the attacker to extract information by purposefully delaying database processing and observing the application's response time.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2160178",
      "url": "https://vulns.co/api/v1/reports/hackerone-2160178/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2160178",
      "record": {
        "id": "hackerone-2160178",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2160178",
        "sourceUrl": "https://hackerone.com/reports/2160178",
        "title": "default credentials at https://52.42.105.71/",
        "program": "Trellix",
        "programUrl": "https://hackerone.com/trellix",
        "reporter": "forcedrofes",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-02-01",
        "submittedAt": "2023-09-16",
        "weakness": "Improper Authentication - Generic",
        "vulnerabilityClass": "identity",
        "summary": "Default credentials were used to gain unauthorized access to a server at the reported IP address. The website was misconfigured, allowing login with default admin account credentials. The password should be changed or account disabled to remediate.",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2262554",
      "url": "https://vulns.co/api/v1/reports/hackerone-2262554/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2262554",
      "record": {
        "id": "hackerone-2262554",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2262554",
        "sourceUrl": "https://hackerone.com/reports/2262554",
        "title": "Critical Unauthenticated Access to Sensitive Employee and Customer Data Including Invoice Details at ████",
        "program": "Mars",
        "programUrl": "https://hackerone.com/mars",
        "reporter": "skoll101",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-01-30",
        "submittedAt": "2023-11-23",
        "weakness": "Improper Authentication - Generic",
        "vulnerabilityClass": "identity",
        "summary": "During a reconnaissance phase, a directory named 'SSO' was discovered on the website ████████. Upon accessing this directory, it redirected to ██████████, where sensitive employee and customer data, including usernames, emails, purchase history, payment history, bills, phone numbers, customer numbers, credit card numbers, and invoice details, were found to be accessible without requiring any authentication. The system also logged the user in automatically without the need for authentication.",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2209130",
      "url": "https://vulns.co/api/v1/reports/hackerone-2209130/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2209130",
      "record": {
        "id": "hackerone-2209130",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2209130",
        "sourceUrl": "https://hackerone.com/reports/2209130",
        "title": "SQL Injection on prod.oidc-proxy.prod.webservices.mozgcp.net via invite_code parameter - Mozilla social inscription",
        "program": "Mozilla",
        "programUrl": "https://hackerone.com/mozilla",
        "reporter": "supr4s",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-01-30",
        "submittedAt": "2023-10-14",
        "weakness": "SQL Injection",
        "vulnerabilityClass": "injection",
        "summary": "A SQL injection vulnerability was found in the invite_code parameter on prod.oidc-proxy.prod.webservices.mozgcp.net during Mozilla social inscription. Adding quotes to the parameter revealed the issue. A time-based blind payload confirmed the vulnerability, allowing arbitrary SQL queries. This could enable reading sensitive data, modifying data, and executing code.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2132183",
      "url": "https://vulns.co/api/v1/reports/hackerone-2132183/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2132183",
      "record": {
        "id": "hackerone-2132183",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2132183",
        "sourceUrl": "https://hackerone.com/reports/2132183",
        "title": "IDOR to account takeover on POST to █████████ by changing member_id parameter",
        "program": "Mars",
        "programUrl": "https://hackerone.com/mars",
        "reporter": "xandsz",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-01-30",
        "submittedAt": "2023-09-01",
        "weakness": "Insecure Direct Object Reference (IDOR)",
        "vulnerabilityClass": "access-control",
        "summary": "Website endpoint was vulnerable to account takeover by changing member ID parameter.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2327238",
      "url": "https://vulns.co/api/v1/reports/hackerone-2327238/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2327238",
      "record": {
        "id": "hackerone-2327238",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2327238",
        "sourceUrl": "https://hackerone.com/reports/2327238",
        "title": "Lack of Tenant Scoping Enables Limited Cross-Tenant Data Querying and Mutation",
        "program": "Enjin",
        "programUrl": "https://hackerone.com/enjin",
        "reporter": "tushar_rec0n",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-01-25",
        "submittedAt": "2024-01-19",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "A vulnerability was demonstrated on the Enjin Platform that allowed for limited cross-tenant data querying and mutation, enabling querying or mutating of someone else's data in certain cases. A full assessment found this had not been exploited outside of the report.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2307933",
      "url": "https://vulns.co/api/v1/reports/hackerone-2307933/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2307933",
      "record": {
        "id": "hackerone-2307933",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2307933",
        "sourceUrl": "https://hackerone.com/reports/2307933",
        "title": "Datadog api keys exposed can be used to do all the read and write access to the instance",
        "program": "Mars",
        "programUrl": "https://hackerone.com/mars",
        "reporter": "harshdranjan",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-01-25",
        "submittedAt": "2024-01-08",
        "weakness": "Information Disclosure",
        "vulnerabilityClass": "data-exposure",
        "summary": "A vulnerability was identified where Datadog API keys were exposed in a JavaScript file, which could have enabled unauthorized access to Datadog services. The issue was responsibly disclosed along with a proof-of-concept demonstration.",
        "hunterAngle": "Identify the intended audience and the narrowest unauthorized observer. Use controlled records, distinguish metadata from secret material, and quantify the repeatable exposure boundary.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2256032",
      "url": "https://vulns.co/api/v1/reports/hackerone-2256032/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2256032",
      "record": {
        "id": "hackerone-2256032",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2256032",
        "sourceUrl": "https://hackerone.com/reports/2256032",
        "title": "SQL injection at ███████",
        "program": "Sony",
        "programUrl": "https://hackerone.com/sony",
        "reporter": "testingforbugs",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-01-24",
        "submittedAt": "2023-11-17",
        "weakness": "SQL Injection",
        "vulnerabilityClass": "injection",
        "summary": "A Sony website was vulnerable to an error-based SQL injection that allowed data extraction.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2255750",
      "url": "https://vulns.co/api/v1/reports/hackerone-2255750/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2255750",
      "record": {
        "id": "hackerone-2255750",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2255750",
        "sourceUrl": "https://hackerone.com/reports/2255750",
        "title": "Remote code execution and exfiltration of secret tokens by poisoning the mozilla/fxa CI build cache",
        "program": "Mozilla",
        "programUrl": "https://hackerone.com/mozilla",
        "reporter": "0x90security",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-01-20",
        "submittedAt": "2023-11-17",
        "weakness": "Code Injection",
        "vulnerabilityClass": "injection",
        "bounty": {
          "value": 8000,
          "currency": "USD"
        },
        "summary": "Remote code execution and data exfiltration were possible by poisoning a cache used in a CI build process. A proof of concept demonstrated the ability to exfiltrate sensitive data by re-uploading a modified cache artifact. The vulnerability required access to the source code repository to be exploited.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2312217",
      "url": "https://vulns.co/api/v1/reports/hackerone-2312217/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2312217",
      "record": {
        "id": "hackerone-2312217",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2312217",
        "sourceUrl": "https://hackerone.com/reports/2312217",
        "title": "Revocation API Token by Bypassing The XSRF Token",
        "program": "Enjin",
        "programUrl": "https://hackerone.com/enjin",
        "reporter": "alpernae",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-01-19",
        "submittedAt": "2024-01-11",
        "weakness": "Cross-Site Request Forgery (CSRF)",
        "vulnerabilityClass": "critical-path",
        "summary": "The revocation API token was bypassed by bypassing the XSRF token. This allowed the demonstration that the Enjin Platform's GraphQL interface lacked appropriate CSRF protection when utilizing a session token.",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2248689",
      "url": "https://vulns.co/api/v1/reports/hackerone-2248689/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2248689",
      "record": {
        "id": "hackerone-2248689",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2248689",
        "sourceUrl": "https://hackerone.com/reports/2248689",
        "title": "Authentication bypass in Global Site Selector allows an attacker to log in as any user",
        "program": "Nextcloud",
        "programUrl": "https://hackerone.com/nextcloud",
        "reporter": "ryotak",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2024-01-18",
        "submittedAt": "2023-11-11",
        "vulnerabilityClass": "identity",
        "cves": [
          "CVE-2024-22212"
        ],
        "summary": "Authentication bypass vulnerability in software allowed attacker to bypass authentication and log in as any user.",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1677047",
      "url": "https://vulns.co/api/v1/reports/hackerone-1677047/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1677047",
      "record": {
        "id": "hackerone-1677047",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1677047",
        "sourceUrl": "https://hackerone.com/reports/1677047",
        "title": "Remote code execution via crafted pentaho report uploaded using default credentials for pentaho business server",
        "program": "MTN Group",
        "programUrl": "https://hackerone.com/mtn_group",
        "reporter": "zer0code",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-12-31",
        "submittedAt": "2022-08-22",
        "weakness": "Code Injection",
        "vulnerabilityClass": "injection",
        "summary": "A remote code execution vulnerability was discovered in Pentaho Business Analytics Server. By uploading a specially crafted Pentaho report file using default credentials, an attacker could achieve arbitrary code execution.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2248328",
      "url": "https://vulns.co/api/v1/reports/hackerone-2248328/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2248328",
      "record": {
        "id": "hackerone-2248328",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2248328",
        "sourceUrl": "https://hackerone.com/reports/2248328",
        "title": "RCE on Wordpress website",
        "program": "Nextcloud",
        "programUrl": "https://hackerone.com/nextcloud",
        "reporter": "lukasreschke",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-12-28",
        "submittedAt": "2023-11-10",
        "weakness": "Deserialization of Untrusted Data",
        "vulnerabilityClass": "code-execution",
        "summary": "A remote code execution vulnerability was exploited on a WordPress website due to unsafe deserialization of user input. This allowed arbitrary code execution as the web server user.",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2262365",
      "url": "https://vulns.co/api/v1/reports/hackerone-2262365/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2262365",
      "record": {
        "id": "hackerone-2262365",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2262365",
        "sourceUrl": "https://hackerone.com/reports/2262365",
        "title": "Default Admin Username and Password on ███",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "maskedpersian",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-12-21",
        "submittedAt": "2023-11-23",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "A vulnerability was found where default administrator credentials could be used to access an application. This could have allowed unauthorized access.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2054184",
      "url": "https://vulns.co/api/v1/reports/hackerone-2054184/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2054184",
      "record": {
        "id": "hackerone-2054184",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2054184",
        "sourceUrl": "https://hackerone.com/reports/2054184",
        "title": "RCE via File Upload with a Null Byte Truncated File Extension at https://██████/",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "pizzapower",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-12-21",
        "submittedAt": "2023-07-06",
        "weakness": "Command Injection - Generic",
        "vulnerabilityClass": "injection",
        "summary": "A remote code execution vulnerability via file upload with a null byte truncated file extension was found on a website. By uploading a file with .asp%00.png extension, malicious ASP code could be executed on the server. This allowed an attacker to run arbitrary system commands. The issue was reported and remediation was suggested.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1327769",
      "url": "https://vulns.co/api/v1/reports/hackerone-1327769/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1327769",
      "record": {
        "id": "hackerone-1327769",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1327769",
        "sourceUrl": "https://hackerone.com/reports/1327769",
        "title": "RCE in ███ [CVE-2021-26084]",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "fdeleite",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-12-21",
        "submittedAt": "2021-09-02",
        "weakness": "OS Command Injection",
        "vulnerabilityClass": "injection",
        "cves": [
          "CVE-2021-26084"
        ],
        "summary": "A vulnerability in affected versions of Confluence Server and Data Center allowed authenticated users, and in some cases unauthenticated users, to execute arbitrary code. The vulnerability was due to an OGNL injection issue affecting endpoints that could be accessed by non-administrators when user signup was enabled. It impacted versions before 6.13.23, from 6.14.0 before 7.4.11, from 7.5.0 before 7.11.6, and from 7.12.0. It allowed remote code execution by attackers. The vulnerability was assigned CVE-2021-26084.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1327701",
      "url": "https://vulns.co/api/v1/reports/hackerone-1327701/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1327701",
      "record": {
        "id": "hackerone-1327701",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1327701",
        "sourceUrl": "https://hackerone.com/reports/1327701",
        "title": "RCE on ███████ [CVE-2021-26084]",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "fdeleite",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-12-21",
        "submittedAt": "2021-09-02",
        "weakness": "OS Command Injection",
        "vulnerabilityClass": "injection",
        "cves": [
          "CVE-2021-26084"
        ],
        "summary": "A remote code execution vulnerability was present in affected versions of Confluence Server and Data Center due to an OGNL injection issue. This allowed an authenticated user, and in some cases an unauthenticated user, to execute arbitrary code. The vulnerability affected versions before 6.13.23, from 6.14.0 before 7.4.11, from 7.5.0 before 7.11.6, and from 7.12.0. It allowed remote code execution by an unauthenticated attacker.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2193815",
      "url": "https://vulns.co/api/v1/reports/hackerone-2193815/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2193815",
      "record": {
        "id": "hackerone-2193815",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2193815",
        "sourceUrl": "https://hackerone.com/reports/2193815",
        "title": "Mozilla Employee's Token for sql.telemetry.mozilla.org Exposed in Git Commit",
        "program": "Mozilla",
        "programUrl": "https://hackerone.com/mozilla",
        "reporter": "yakirka",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-12-18",
        "submittedAt": "2023-10-04",
        "weakness": "Cleartext Storage of Sensitive Information",
        "vulnerabilityClass": "critical-path",
        "summary": "A Mozilla employee's API token was exposed in a GitHub repository, granting access to confidential data. The token was rotated and removed from the service.",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2262382",
      "url": "https://vulns.co/api/v1/reports/hackerone-2262382/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2262382",
      "record": {
        "id": "hackerone-2262382",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2262382",
        "sourceUrl": "https://hackerone.com/reports/2262382",
        "title": "Server Side Request Forgery (SSRF) via Analytics Reports",
        "program": "HackerOne",
        "programUrl": "https://hackerone.com/security",
        "reporter": "megaman_",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-12-08",
        "submittedAt": "2023-11-23",
        "weakness": "Server-Side Request Forgery (SSRF)",
        "vulnerabilityClass": "ssrf",
        "bounty": {
          "value": 25000,
          "currency": "USD"
        },
        "summary": "We recently received a critical server-side request forgery (SSRF) vulnerability report through our bug bounty program. The issue allowed attackers to make internal requests from our application servers by exploiting a lack of output sanitization in an error message. By crafting malicious requests, an attacker could have accessed internal AWS services and obtained temporary credentials. Upon receiving the report, we were able to reproduce and verify the issue. We have implemented a fix that is now deployed in production. We have also added regression tests to prevent future occurrences of this vulnerability. Our forensic investigation concluded that there is no evidence this issue was exploited prior to the report. We have rated this vulnerability CVSSv3 10 (Critical) based on the potential impact of exposed credentials. Based on the severity, business impact, and quality of this report…",
        "hunterAngle": "Map URL parsing, redirects, DNS resolution, and egress as separate decisions. Use an owned callback and compare it with a non-routable control without probing unrelated internal services.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2192984",
      "url": "https://vulns.co/api/v1/reports/hackerone-2192984/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2192984",
      "record": {
        "id": "hackerone-2192984",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2192984",
        "sourceUrl": "https://hackerone.com/reports/2192984",
        "title": "Unauthenticated Remote Access to Testing Endpoint",
        "program": "IBM",
        "programUrl": "https://hackerone.com/ibm",
        "reporter": "sajidraza",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-12-04",
        "submittedAt": "2023-10-04",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "Unauthenticated remote access to a testing endpoint was reported, analyzed and remediated.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2030076",
      "url": "https://vulns.co/api/v1/reports/hackerone-2030076/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2030076",
      "record": {
        "id": "hackerone-2030076",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2030076",
        "sourceUrl": "https://hackerone.com/reports/2030076",
        "title": "Mozilla FuzzManager API Token Exposed in Git Commit",
        "program": "Mozilla",
        "programUrl": "https://hackerone.com/mozilla",
        "reporter": "yakirka",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-11-29",
        "submittedAt": "2023-06-17",
        "weakness": "Cleartext Storage of Sensitive Information",
        "vulnerabilityClass": "critical-path",
        "summary": "An API token for a Mozilla fuzzing service was exposed in a GitHub repository commit. The token provided read-write access to internal fuzzing data. The token was rotated and configured for write-only access.",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-263663",
      "url": "https://vulns.co/api/v1/reports/hackerone-263663/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-263663",
      "record": {
        "id": "hackerone-263663",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "263663",
        "sourceUrl": "https://hackerone.com/reports/263663",
        "title": "Zip bomb",
        "program": "Tor",
        "programUrl": "https://hackerone.com/torproject",
        "reporter": "zerx",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-11-28",
        "submittedAt": "2017-08-26",
        "weakness": "Incorrect Calculation of Buffer Size",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2051931",
      "url": "https://vulns.co/api/v1/reports/hackerone-2051931/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2051931",
      "record": {
        "id": "hackerone-2051931",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2051931",
        "sourceUrl": "https://hackerone.com/reports/2051931",
        "title": "Blind SQL injection on id.indrive.com",
        "program": "inDrive",
        "programUrl": "https://hackerone.com/indrive",
        "reporter": "kristoferent",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-11-24",
        "submittedAt": "2023-07-06",
        "weakness": "Blind SQL Injection",
        "vulnerabilityClass": "injection",
        "bounty": {
          "value": 4134,
          "currency": "USD"
        },
        "summary": "A blind SQL injection vulnerability was found where user input was not sanitized before being used in SQL queries. This allowed arbitrary SQL commands to be injected, revealing details of the backend database.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2252307",
      "url": "https://vulns.co/api/v1/reports/hackerone-2252307/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2252307",
      "record": {
        "id": "hackerone-2252307",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2252307",
        "sourceUrl": "https://hackerone.com/reports/2252307",
        "title": "Buffer overflow and affected url:-https://github.com/curl/curl/blob/master/docs/examples/hsts-preload.c",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "cyberguardianrd",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-11-15",
        "submittedAt": "2023-11-15",
        "weakness": "Classic Buffer Overflow",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2190808",
      "url": "https://vulns.co/api/v1/reports/hackerone-2190808/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2190808",
      "record": {
        "id": "hackerone-2190808",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2190808",
        "sourceUrl": "https://hackerone.com/reports/2190808",
        "title": "User automatically logged in as Sys Admin user on https://███/Administration/Administration.aspx",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "mrr0b0t2324",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-11-03",
        "submittedAt": "2023-10-03",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "A vulnerability was discovered where any user could be automatically logged in as a system administrator on a web application. This allowed unrestricted access and privileges could be abused to modify user privileges, add or delete users, and upload files, jeopardizing the integrity of the application. The issue was remediated by requiring authentication before granting administrative access.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2199174",
      "url": "https://vulns.co/api/v1/reports/hackerone-2199174/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2199174",
      "record": {
        "id": "hackerone-2199174",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2199174",
        "sourceUrl": "https://hackerone.com/reports/2199174",
        "title": "[Critical] Curl CVE-2023-38545 vulnerability code changes are disclosed on the internet",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "shelldoit",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-10-16",
        "submittedAt": "2023-10-10",
        "weakness": "Information Disclosure",
        "vulnerabilityClass": "data-exposure",
        "hunterAngle": "Identify the intended audience and the narrowest unauthorized observer. Use controlled records, distinguish metadata from secret material, and quantify the repeatable exposure boundary.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1977252",
      "url": "https://vulns.co/api/v1/reports/hackerone-1977252/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1977252",
      "record": {
        "id": "hackerone-1977252",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1977252",
        "sourceUrl": "https://hackerone.com/reports/1977252",
        "title": "UAF on JSEthereumProvider",
        "program": "Brave Software",
        "programUrl": "https://hackerone.com/brave",
        "reporter": "nick0ve",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-10-11",
        "submittedAt": "2023-05-08",
        "weakness": "Use After Free",
        "vulnerabilityClass": "critical-path",
        "bounty": {
          "value": 3000,
          "currency": "USD"
        },
        "summary": "A UAF (Use After Free) vulnerability was discovered in the renderer implementation of the Ethereum wallet. This vulnerability allowed an attacker to trigger a crash in the renderer process and potentially execute arbitrary code.",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-560668",
      "url": "https://vulns.co/api/v1/reports/hackerone-560668/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-560668",
      "record": {
        "id": "hackerone-560668",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "560668",
        "sourceUrl": "https://hackerone.com/reports/560668",
        "title": "Access to resumes applied through LinkedIn Jobs",
        "program": "LinkedIn",
        "programUrl": "https://hackerone.com/linkedin",
        "reporter": "headhunter",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-09-22",
        "submittedAt": "2019-05-02",
        "weakness": "Information Disclosure",
        "vulnerabilityClass": "data-exposure",
        "hunterAngle": "Identify the intended audience and the narrowest unauthorized observer. Use controlled records, distinguish metadata from secret material, and quantify the repeatable exposure boundary.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1639600",
      "url": "https://vulns.co/api/v1/reports/hackerone-1639600/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1639600",
      "record": {
        "id": "hackerone-1639600",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1639600",
        "sourceUrl": "https://hackerone.com/reports/1639600",
        "title": "Hashed data exposure via WebSockets to Workspace Members",
        "program": "Slack",
        "programUrl": "https://hackerone.com/slack",
        "reporter": "d3f4u17",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-09-21",
        "submittedAt": "2022-07-17",
        "weakness": "Insufficiently Protected Credentials",
        "vulnerabilityClass": "critical-path",
        "summary": "A vulnerability in Slack's system allowed for the exposure of members' email addresses and sensitive data through WebSockets. This occurred when users created or revoked a Shared Invite Link for their workspace, resulting in the transmission of hashed passwords to other workspace members. The issue was promptly addressed, with affected users' passwords reset and notifications sent to customers.",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2171309",
      "url": "https://vulns.co/api/v1/reports/hackerone-2171309/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2171309",
      "record": {
        "id": "hackerone-2171309",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2171309",
        "sourceUrl": "https://hackerone.com/reports/2171309",
        "title": "NULL Pointer dereference in idn.c",
        "program": "curl",
        "programUrl": "https://hackerone.com/curl",
        "reporter": "s0urc3_",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-09-20",
        "submittedAt": "2023-09-19",
        "weakness": "NULL Pointer Dereference",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-2085185",
      "url": "https://vulns.co/api/v1/reports/hackerone-2085185/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-2085185",
      "record": {
        "id": "hackerone-2085185",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "2085185",
        "sourceUrl": "https://hackerone.com/reports/2085185",
        "title": "IDOR in upload videos of a Channel on https://video.ibm.com",
        "program": "IBM",
        "programUrl": "https://hackerone.com/ibm",
        "reporter": "tusnj",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-08-31",
        "submittedAt": "2023-07-26",
        "weakness": "Insecure Direct Object Reference (IDOR)",
        "vulnerabilityClass": "access-control",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1688309",
      "url": "https://vulns.co/api/v1/reports/hackerone-1688309/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1688309",
      "record": {
        "id": "hackerone-1688309",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1688309",
        "sourceUrl": "https://hackerone.com/reports/1688309",
        "title": "[MK8DX] Improper metadata parsing",
        "program": "Nintendo",
        "programUrl": "https://hackerone.com/nintendo",
        "reporter": "crazy_man123",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-08-17",
        "submittedAt": "2022-09-01",
        "weakness": "NULL Pointer Dereference",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1791720",
      "url": "https://vulns.co/api/v1/reports/hackerone-1791720/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1791720",
      "record": {
        "id": "hackerone-1791720",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1791720",
        "sourceUrl": "https://hackerone.com/reports/1791720",
        "title": "Ad Account Takeover",
        "program": "LinkedIn",
        "programUrl": "https://hackerone.com/linkedin",
        "reporter": "them4les_l1r",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-07-20",
        "submittedAt": "2022-12-04",
        "weakness": "Privilege Escalation",
        "vulnerabilityClass": "access-control",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1049367",
      "url": "https://vulns.co/api/v1/reports/hackerone-1049367/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1049367",
      "record": {
        "id": "hackerone-1049367",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1049367",
        "sourceUrl": "https://hackerone.com/reports/1049367",
        "title": "Server-side RCE through directory traversal-based arbitrary file write",
        "program": "Rocket.Chat",
        "programUrl": "https://hackerone.com/rocket_chat",
        "reporter": "fabianfreyer",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-07-10",
        "submittedAt": "2020-12-03",
        "weakness": "Path Traversal",
        "vulnerabilityClass": "code-execution",
        "hunterAngle": "Separate the reachable primitive from the final impact. Prove execution with a side-effect-free marker, record the trust boundary, and stop before persistence or lateral movement.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1785145",
      "url": "https://vulns.co/api/v1/reports/hackerone-1785145/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1785145",
      "record": {
        "id": "hackerone-1785145",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1785145",
        "sourceUrl": "https://hackerone.com/reports/1785145",
        "title": "Full access to InDrive jira panel via exposed API token",
        "program": "inDrive",
        "programUrl": "https://hackerone.com/indrive",
        "reporter": "bogdantc",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-06-28",
        "submittedAt": "2022-11-27",
        "weakness": "Information Disclosure",
        "vulnerabilityClass": "data-exposure",
        "bounty": {
          "value": 1500,
          "currency": "USD"
        },
        "summary": "The Jira API token was exposed in a GitHub repository, allowing unauthorized access to the InDrive Atlassian panel and sensitive information stored in Jira.",
        "hunterAngle": "Identify the intended audience and the narrowest unauthorized observer. Use controlled records, distinguish metadata from secret material, and quantify the repeatable exposure boundary.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1959540",
      "url": "https://vulns.co/api/v1/reports/hackerone-1959540/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1959540",
      "record": {
        "id": "hackerone-1959540",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1959540",
        "sourceUrl": "https://hackerone.com/reports/1959540",
        "title": "' Full Account Takeover ' at █████",
        "program": "Mars",
        "programUrl": "https://hackerone.com/mars",
        "reporter": "0xs4m",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-06-23",
        "submittedAt": "2023-04-23",
        "weakness": "Improper Access Control - Generic",
        "vulnerabilityClass": "access-control",
        "summary": "A severe vulnerability was identified in the login functionality of a website belonging to Mars. An unauthorized actor could manipulate the server's response from the ██████████ endpoint to gain unauthorized access to any user account on the platform, leading to a full account takeover.",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1716016",
      "url": "https://vulns.co/api/v1/reports/hackerone-1716016/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1716016",
      "record": {
        "id": "hackerone-1716016",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1716016",
        "sourceUrl": "https://hackerone.com/reports/1716016",
        "title": "Ability to join an arbitrary workspace by utilizing a proxy to manipulate invite links",
        "program": "Slack",
        "programUrl": "https://hackerone.com/slack",
        "reporter": "hunter0xp7",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-06-23",
        "submittedAt": "2022-09-28",
        "weakness": "Improper Authentication - Generic",
        "vulnerabilityClass": "identity",
        "summary": "A vulnerability was found in Slack that allowed experienced researchers to utilize an intercepting proxy to manipulate invite links and join an arbitrary workspace without admin approval. The issue was fixed immediately and no customers were impacted.",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1436142",
      "url": "https://vulns.co/api/v1/reports/hackerone-1436142/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1436142",
      "record": {
        "id": "hackerone-1436142",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1436142",
        "sourceUrl": "https://hackerone.com/reports/1436142",
        "title": "New XSS vector in ReaderMode with %READER-TITLE-NONCE%",
        "program": "Brave Software",
        "programUrl": "https://hackerone.com/brave",
        "reporter": "nishimunea",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-06-22",
        "submittedAt": "2021-12-26",
        "weakness": "Cross-site Scripting (XSS) - Generic",
        "vulnerabilityClass": "browser-injection",
        "summary": "A new XSS vulnerability was discovered in Brave iOS 1.31.1 and higher, which allowed attackers to execute malicious scripts on ReaderMode pages. The vulnerability was caused by a relaxation of the CSP rule, which allowed scripts with `nonce-%READER-TITLE-NONCE%` to be executed. Attackers could exploit the `%READER-CREDITS%` vector to embed a malicious script in the `<meta name=\"author\">` tag, which would execute when the page was displayed in ReaderMode. This vulnerability could allow attackers to steal cross-origin pages that had been converted to ReaderMode and gain access to Brave's privileged pages.",
        "hunterAngle": "Locate the exact browser sink and encoding context. Prove execution with a harmless marker, then test whether privilege, origin, or persistence changes the impact.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1994227",
      "url": "https://vulns.co/api/v1/reports/hackerone-1994227/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1994227",
      "record": {
        "id": "hackerone-1994227",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1994227",
        "sourceUrl": "https://hackerone.com/reports/1994227",
        "title": "response manipulation leads to bypass in register at employee website than 0 click account takeover",
        "program": "IBM",
        "programUrl": "https://hackerone.com/ibm",
        "reporter": "ro0od",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-06-21",
        "submittedAt": "2023-05-19",
        "weakness": "Improper Authentication - Generic",
        "vulnerabilityClass": "identity",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1952124",
      "url": "https://vulns.co/api/v1/reports/hackerone-1952124/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1952124",
      "record": {
        "id": "hackerone-1952124",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1952124",
        "sourceUrl": "https://hackerone.com/reports/1952124",
        "title": "Cloudflare CASB Confused Deputy Problem",
        "program": "Cloudflare Public Bug Bounty",
        "programUrl": "https://hackerone.com/cloudflare",
        "reporter": "albertspedersen",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-06-07",
        "submittedAt": "2023-04-18",
        "vulnerabilityClass": "critical-path",
        "bounty": {
          "value": 3300,
          "currency": "USD"
        },
        "summary": "A vulnerability was found in Cloudflare CASB on Microsoft and GitHub integrations, allowing an attacker to create a new integration and access sensitive information if they were able to enumerate a valid tenant UUID or domain. The issue was resolved by disallowing the creation of multiple integrations pointing to the same tenant.",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1744264",
      "url": "https://vulns.co/api/v1/reports/hackerone-1744264/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1744264",
      "record": {
        "id": "hackerone-1744264",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1744264",
        "sourceUrl": "https://hackerone.com/reports/1744264",
        "title": "read and message other user's messages",
        "program": "Reddit",
        "programUrl": "https://hackerone.com/reddit",
        "reporter": "beksem35",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-05-18",
        "submittedAt": "2022-10-20",
        "weakness": "Insecure Direct Object Reference (IDOR)",
        "vulnerabilityClass": "access-control",
        "hunterAngle": "Build an owner, peer, tenant, and privileged role matrix. Replay the same controlled object or action and identify the first authorization layer that disagrees.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1719588",
      "url": "https://vulns.co/api/v1/reports/hackerone-1719588/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1719588",
      "record": {
        "id": "hackerone-1719588",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1719588",
        "sourceUrl": "https://hackerone.com/reports/1719588",
        "title": "HTML injection in API response including request url",
        "program": "Reddit",
        "programUrl": "https://hackerone.com/reddit",
        "reporter": "prilvesh",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-05-18",
        "submittedAt": "2022-10-02",
        "weakness": "Remote File Inclusion",
        "vulnerabilityClass": "injection",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-715949",
      "url": "https://vulns.co/api/v1/reports/hackerone-715949/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-715949",
      "record": {
        "id": "hackerone-715949",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "715949",
        "sourceUrl": "https://hackerone.com/reports/715949",
        "title": "[HTA2] XXE on https://███ via SpellCheck Endpoint.",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "cdl",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-05-15",
        "submittedAt": "2019-10-16",
        "weakness": "XML External Entities (XXE)",
        "vulnerabilityClass": "critical-path",
        "summary": "A full read XXE vulnerability was discovered on a website via the SpellCheck endpoint, allowing an attacker to read local files, make HTTP requests to internal applications and read the responses, steal NTLM hashes, and also completely deny service to the application.",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1938693",
      "url": "https://vulns.co/api/v1/reports/hackerone-1938693/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1938693",
      "record": {
        "id": "hackerone-1938693",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1938693",
        "sourceUrl": "https://hackerone.com/reports/1938693",
        "title": "Default Credentials on Kinetic Core System Console - https://█████/kinetic/app/",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "waterlord7788",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-05-15",
        "submittedAt": "2023-04-07",
        "weakness": "Use of Default Credentials",
        "vulnerabilityClass": "critical-path",
        "summary": "Weak default credentials of \"admin/admin\" were discovered on the Kinetic Core System Console application, potentially allowing attackers to identify underlying technologies and access sensitive information such as server logs and user data. The vulnerability was present in version 2.1.0-SNAPSHOT. The suggested mitigation action is to change the admin password to a more secure one.",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1912671",
      "url": "https://vulns.co/api/v1/reports/hackerone-1912671/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1912671",
      "record": {
        "id": "hackerone-1912671",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1912671",
        "sourceUrl": "https://hackerone.com/reports/1912671",
        "title": "Sensitive Data Exposure via wp-config.php file",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "0r10nh4ck",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-05-15",
        "submittedAt": "2023-03-20",
        "weakness": "Information Disclosure",
        "vulnerabilityClass": "data-exposure",
        "summary": "Sensitive data exposure occurred via the wp-config.php file, which contained confidential information such as MySQL and AWS credentials and various keys. The vulnerability was found on a specific endpoint, and it could potentially provide unauthorized access to sensitive information to users who do not need it. Access control implementation was suggested as a mitigation action.",
        "hunterAngle": "Identify the intended audience and the narrowest unauthorized observer. Use controlled records, distinguish metadata from secret material, and quantify the repeatable exposure boundary.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1629822",
      "url": "https://vulns.co/api/v1/reports/hackerone-1629822/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1629822",
      "record": {
        "id": "hackerone-1629822",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1629822",
        "sourceUrl": "https://hackerone.com/reports/1629822",
        "title": "Exposed GIT repo on ██████████[HtUS]",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "nightm4re",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-05-15",
        "submittedAt": "2022-07-07",
        "weakness": "Cleartext Storage of Sensitive Information",
        "vulnerabilityClass": "critical-path",
        "hunterAngle": "Reconstruct the preconditions, trust boundary, cheapest decisive test, negative control, and minimal proven impact before exploring any escalation path.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1072832",
      "url": "https://vulns.co/api/v1/reports/hackerone-1072832/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1072832",
      "record": {
        "id": "hackerone-1072832",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1072832",
        "sourceUrl": "https://hackerone.com/reports/1072832",
        "title": "[hta3] Remote Code Execution on ████",
        "program": "U.S. Dept Of Defense",
        "programUrl": "https://hackerone.com/deptofdefense",
        "reporter": "cdl",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-05-15",
        "submittedAt": "2021-01-06",
        "weakness": "Code Injection",
        "vulnerabilityClass": "injection",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1954364",
      "url": "https://vulns.co/api/v1/reports/hackerone-1954364/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1954364",
      "record": {
        "id": "hackerone-1954364",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1954364",
        "sourceUrl": "https://hackerone.com/reports/1954364",
        "title": "Subdomain Takeover Affecting at vex.weather.com",
        "program": "IBM",
        "programUrl": "https://hackerone.com/ibm",
        "reporter": "gdattacker",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-05-10",
        "submittedAt": "2023-04-19",
        "weakness": "Improper Authentication - Generic",
        "vulnerabilityClass": "identity",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1935151",
      "url": "https://vulns.co/api/v1/reports/hackerone-1935151/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1935151",
      "record": {
        "id": "hackerone-1935151",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1935151",
        "sourceUrl": "https://hackerone.com/reports/1935151",
        "title": "SQL Injection at https://████ via ███ parameter",
        "program": "Sony",
        "programUrl": "https://hackerone.com/sony",
        "reporter": "kauenavarro",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-04-24",
        "submittedAt": "2023-04-05",
        "weakness": "SQL Injection",
        "vulnerabilityClass": "injection",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1878584",
      "url": "https://vulns.co/api/v1/reports/hackerone-1878584/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1878584",
      "record": {
        "id": "hackerone-1878584",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1878584",
        "sourceUrl": "https://hackerone.com/reports/1878584",
        "title": "Time Based SQL Injection",
        "program": "U.S. Department of State",
        "programUrl": "https://hackerone.com/us-department-of-state",
        "reporter": "shadow-krd",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-04-20",
        "submittedAt": "2023-02-18",
        "weakness": "SQL Injection",
        "vulnerabilityClass": "injection",
        "summary": "The text describes a Time-Based SQL Injection vulnerability that was identified on the website. The vulnerability was found in the search functionality, where the SQL query was susceptible to injection. A proof of concept was generated using the sqlmap tool to demonstrate the vulnerability.",
        "hunterAngle": "Follow the value across each parser and execution boundary. Change one encoding or delimiter at a time, use harmless canaries, and preserve a clean control response.",
        "reviewStatus": "source-published"
      }
    },
    {
      "id": "report:hackerone-1889161",
      "url": "https://vulns.co/api/v1/reports/hackerone-1889161/",
      "webUrl": "https://vulns.co/reports/#report-hackerone-1889161",
      "record": {
        "id": "hackerone-1889161",
        "source": "hackerone",
        "sourceLabel": "HackerOne",
        "sourceId": "1889161",
        "sourceUrl": "https://hackerone.com/reports/1889161",
        "title": "JWT audience claim is not verified",
        "program": "Internet Bug Bounty",
        "programUrl": "https://hackerone.com/ibb",
        "reporter": "farcaller",
        "severityLabel": "Critical",
        "severitySystem": "HackerOne severity",
        "severityBasis": "source-native",
        "disclosedAt": "2023-04-16",
        "submittedAt": "2023-02-28",
        "weakness": "Missing Critical Step in Authentication",
        "vulnerabilityClass": "identity",
        "cves": [
          "CVE-2023-22482"
        ],
        "summary": "An improper authorization vulnerability existed in all versions of Argo CD starting with v1.8.2, allowing the API to accept certain invalid tokens due to the lack of validation of the audience claim in signed tokens. This could allow an attacker to use a stolen token intended for a different audience to access Argo CD and gain privileges based on the token's groups claim. The vulnerability was patched in versions v2.6.0-rc5, v2.5.8, v2.4.20, and v2.3.14.",
        "hunterAngle": "Model the identity flow as state transitions. Compare two controlled accounts while varying token owner, reuse, expiry, redirect binding, and session rotation one property at a time.",
        "reviewStatus": "source-published"
      }
    }
  ]
}
