vulns.co
/
GKData.io MCP

DEInformation exposure and response privacy · 3 min read

Framework serialization change exposed private HackerOne user attributes

A framework upgrade exposed private contributor attributes in public report responses. The vendor confirmed a USD 25,000 award; the public report supplies the underlying serialization and test-normalization explanation.

Read the primary source DEInformation exposure and response privacyReviewed 2026-10-03

Root cause

The vendor explains that an internal user object and a sanitized public representation shared a field name under different Ruby key types. Earlier serialization retained only the sanitized representation; the upgrade emitted both. Snapshot tests reparsed the response and discarded the earlier duplicate field, concealing sensitive data present in the raw response. The affected context was a disclosed report with a reporter or team-member summary. This was an application output-boundary failure exposed by a framework behavior change, not an AI-agent defect.

Demonstrated impact

The vendor reproduced private-attribute exposure. The public report describes personal and security-sensitive account attributes, but does not demonstrate account takeover or establish an affected-user count or wider exploitation. The vendor announced a deployed fix on February 21, 2025; the researcher retested and observed only intended public attributes for team and reporter summaries. The exact code change is not disclosed.

Lessons for review

  • Editorial lesson: construct public responses from explicit safe fields rather than relying on later serialization to overwrite an internal object.
  • Editorial lesson: test both raw serialized output and parsed structure; normalization can hide duplicate fields and sensitive data.
  • Editorial lesson: treat framework upgrades as changes to security-relevant output semantics, and exercise nested representations with private-field exclusion assertions.

Award and evidence

USD 25,000Bug Bounty · Vendor Confirmed

Vendor confirms the individual report’s reward; the public report records the award event on February 21, 2025, while settlement remains unreported. The award article uses a dollar sign; current official HackerOne standards supply USD context only. Exhibit C reproduces guideline version 1.2 dated July 29, 2019 and specifies USD on printed page 12, supplying historical platform context rather than individual payment proof.

Freshly read the vendor case study and the public technical report in the cloud browser, including vendor root-cause explanation and timeline. No target testing. Existing denomination sources retained without a fresh review.

  • Award evidence does not establish settlement; the USD 25,000 amount comes from the case study, while the report hides the bounty amount.
  • The technical report names the earlier Rails version as 6.1.7.9; the later case study says 6.1.7.10. Both identify the upgrade to 7.1.5.1; the discrepancy is unresolved.
  • The case study describes retest validation within an hour, but visible retest-request and completion timestamps are about 72 minutes apart. Edited timeline timestamps and deployment timing limit precise duration comparisons.
  • The public sources do not establish exact authentication prerequisites, affected-user count, a code-level patch, or successful account compromise.
  • Currency context includes currently reviewed standards dated July 27, 2026 and historical platform guidelines; neither independently proves individual settlement.

Recorded timeline

Published
2025-04-01explicit · Public technical report disclosure date; the later vendor case study was published June 24, 2025.
Public Disclosure
2025-04-01explicit
Reported
2025-02-19explicit
Awarded
2025-02-21explicit · Public timeline records the bounty event; the vendor case study establishes its USD 25,000 amount. Separate retest compensation is not included.
Fixed
2025-02-21explicit · Vendor deployment confirmation and successful researcher retest appear on this day; exact deployment time is not established.

Related visual models

Sources and provenance

  1. We’re Running Hai Insight Agent on Our Own Bug Bounty Program – See it in Action Crystal Hazen / HackerOne · reviewed 2026-10-03
  2. Vulnerability Disclosure Standards HackerOne · reviewed 2026-10-02
  3. HackerOne terms and disclosure guidelines in official reseller GSA contract attachment, Exhibit C HackerOne / Carahsoft (contract attachment) · reviewed 2026-10-02
  4. Public report 3000510: private user attributes exposed in report serialization HackerOne and avinash_ · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software