🏦 SingleStore Report
📝 Title: Insecure Direct Object Reference \(IDOR\) allows creating folders.
🔍 Reporter: bl4ck- (Ali Abbas)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Low
└ 🎯 CWE: Insecure Direct Object Reference \(IDOR\)
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-01 17:41:16 UTC
└ 📝 Created: 2025-09-22 06:00:57 UTC
📝 Title: Insecure Direct Object Reference \(IDOR\) allows creating folders.
🔍 Reporter: bl4ck- (Ali Abbas)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Low
└ 🎯 CWE: Insecure Direct Object Reference \(IDOR\)
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-01 17:41:16 UTC
└ 📝 Created: 2025-09-22 06:00:57 UTC
HackerOne
SingleStore disclosed on HackerOne: Insecure Direct Object...
An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SingleStore's backend API that allowed authenticated users with low privileges to create unauthorized folders and files in...
🏦 SingleStore Report
📝 Title: Delete any folder for any user within the organization
🔍 Reporter: bl4ck- (Ali Abbas)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Low
└ 🎯 CWE: Insecure Direct Object Reference \(IDOR\)
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-01 17:39:22 UTC
└ 📝 Created: 2025-09-22 05:08:14 UTC
📝 Title: Delete any folder for any user within the organization
🔍 Reporter: bl4ck- (Ali Abbas)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Low
└ 🎯 CWE: Insecure Direct Object Reference \(IDOR\)
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-01 17:39:22 UTC
└ 📝 Created: 2025-09-22 05:08:14 UTC
HackerOne
SingleStore disclosed on HackerOne: Delete any folder for any user...
An IDOR vulnerability in the SingleStore backend API allowed low-privileged users to delete folders belonging to other users within the same organization by manipulating the folder_id parameter in...
🔥1
🏦 SingleStore Report
📝 Title: Privilege Escalation – Access to the Alert Subscribers page for users with low privileges
🔍 Reporter: bl4ck- (Ali Abbas)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Low
└ 🎯 CWE: Privilege Escalation
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-01 17:36:56 UTC
└ 📝 Created: 2025-09-22 03:30:31 UTC
📝 Title: Privilege Escalation – Access to the Alert Subscribers page for users with low privileges
🔍 Reporter: bl4ck- (Ali Abbas)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Low
└ 🎯 CWE: Privilege Escalation
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-01 17:36:56 UTC
└ 📝 Created: 2025-09-22 03:30:31 UTC
HackerOne
SingleStore disclosed on HackerOne: Privilege Escalation – Access...
A privilege escalation vulnerability in the SingleStore Helios alert management system allowed users with low privileges to access the Alert Subscribers API endpoint and retrieve email addresses...
❤1👍1
🏦 Nintendo Report
⚠️ Title: Splatoon 3 In-Match Integrity Bypass via Consensus Reflection Attack on Unordered Peer Submission
🔍 Reporter: hana2736 (Hana)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: High
└ 🎯 CWE: Client-Side Enforcement of Server-Side Security
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-02 01:26:11 UTC
└ 📝 Created: 2026-02-17 20:01:19 UTC
⚠️ Title: Splatoon 3 In-Match Integrity Bypass via Consensus Reflection Attack on Unordered Peer Submission
🔍 Reporter: hana2736 (Hana)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: High
└ 🎯 CWE: Client-Side Enforcement of Server-Side Security
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-02 01:26:11 UTC
└ 📝 Created: 2026-02-17 20:01:19 UTC
HackerOne
Nintendo disclosed on HackerOne: Splatoon 3 In-Match Integrity...
❤1
🏦 Nintendo Report
⚡ Title: \[Splatoon 3\ Kick other players with NplnLogin message](https://hackerone.com/reports/3813932)
🔍 Reporter: alzxk11 (Alex)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Medium
└ 🎯 CWE: Improper Access Control - Generic
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-02 01:25:44 UTC
└ 📝 Created: 2026-06-20 09:49:38 UTC
⚡ Title: \[Splatoon 3\ Kick other players with NplnLogin message](https://hackerone.com/reports/3813932)
🔍 Reporter: alzxk11 (Alex)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Medium
└ 🎯 CWE: Improper Access Control - Generic
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-02 01:25:44 UTC
└ 📝 Created: 2026-06-20 09:49:38 UTC
HackerOne
Nintendo disclosed on HackerOne: [Splatoon 3] Kick other players...
-
❤1
🏦 8x8 Report
📝 Title: jitsi-call-analytics: Unauthenticated arbitrary file write via path traversal in \`/api/v1/uploads/analyze\`
🔍 Reporter: r1skr1der (zhixin)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Low
└ 🎯 CWE: Path Traversal
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-02 15:41:33 UTC
└ 📝 Created: 2026-01-03 02:38:16 UTC
📝 Title: jitsi-call-analytics: Unauthenticated arbitrary file write via path traversal in \`/api/v1/uploads/analyze\`
🔍 Reporter: r1skr1der (zhixin)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Low
└ 🎯 CWE: Path Traversal
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-02 15:41:33 UTC
└ 📝 Created: 2026-01-03 02:38:16 UTC
HackerOne
8x8 disclosed on HackerOne: jitsi-call-analytics: Unauthenticated...
The jitsi-call-analytics backend contained a path traversal vulnerability in the `/api/v1/uploads/analyze` endpoint that allowed unauthenticated users to write files within the configured...
🏦 Yelp Report
⚡ Title: Yelp for Business: locked Email field silently editable via API
🔍 Reporter: 0xmanticore (Saleh Elsayed)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Medium
└ 🎯 CWE: Client-Side Enforcement of Server-Side Security
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-02 15:36:44 UTC
└ 📝 Created: 2026-05-28 09:34:40 UTC
⚡ Title: Yelp for Business: locked Email field silently editable via API
🔍 Reporter: 0xmanticore (Saleh Elsayed)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Medium
└ 🎯 CWE: Client-Side Enforcement of Server-Side Security
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-02 15:36:44 UTC
└ 📝 Created: 2026-05-28 09:34:40 UTC
HackerOne
Yelp disclosed on HackerOne: Yelp for Business: locked Email field...
## Description
The Account Information screen in the Yelp Biz Android app renders the Email field as read-only with a lock icon; the screen exposes no editor. The Save action calls `POST...
The Account Information screen in the Yelp Biz Android app renders the Email field as read-only with a lock icon; the screen exposes no editor. The Save action calls `POST...
🏦 8x8 Report
📝 Title: jitsi-meet: Prosody/Jigasi missing header whitelist in mod\_filter\_iq\_rayo allows arbitrary SIP header injection and Caller ID spoofing
🔍 Reporter: pmgjoe (MRsheep)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Low
└ 🎯 CWE: Improper Input Validation
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-02 15:50:32 UTC
└ 📝 Created: 2026-06-08 12:27:42 UTC
📝 Title: jitsi-meet: Prosody/Jigasi missing header whitelist in mod\_filter\_iq\_rayo allows arbitrary SIP header injection and Caller ID spoofing
🔍 Reporter: pmgjoe (MRsheep)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Low
└ 🎯 CWE: Improper Input Validation
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-02 15:50:32 UTC
└ 📝 Created: 2026-06-08 12:27:42 UTC
HackerOne
8x8 disclosed on HackerOne: jitsi-meet: Prosody/Jigasi missing...
Jitsi Meet's Prosody and Jigasi components contained a SIP header injection vulnerability in the interaction between `mod_filter_iq_rayo.lua` and the call handling backend. The Prosody filter...
🏦 AWS VDP Report
⚡ Title: Non-Production API Endpoints for the Amazon S3 Tables Service Fails to Log to CloudTrail Resulting in Silent Permission Enumeration
🔍 Reporter: nick_frichette_dd (Nick Frichette \(Datadog\))
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Medium
└ 🎯 CWE: Insufficient Logging
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-02 17:51:21 UTC
└ 📝 Created: 2026-06-03 17:00:17 UTC
⚡ Title: Non-Production API Endpoints for the Amazon S3 Tables Service Fails to Log to CloudTrail Resulting in Silent Permission Enumeration
🔍 Reporter: nick_frichette_dd (Nick Frichette \(Datadog\))
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Medium
└ 🎯 CWE: Insufficient Logging
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-02 17:51:21 UTC
└ 📝 Created: 2026-06-03 17:00:17 UTC
HackerOne
AWS VDP disclosed on HackerOne: Non-Production API Endpoints for...
**Summary:** Typically, when an adversary gains access to stolen AWS IAM credentials they will [frequently](https://sysdig.com/blog/scarleteel-2-0/) test those credentials to see what access they...
❤1👏1
🏦 Shopify Report
📋 Title: admin.shopify.com: Shopify Flow continues sending internal emails to a configured recipient after the staff author is removed
🔍 Reporter: abahack (Emmanuel Abah)
📋 Details:
└ 📊 Status: informative
└ ⚡ Severity: None
└ 🎯 CWE: Not Specified
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-03 18:50:06 UTC
└ 📝 Created: 2026-03-26 10:49:30 UTC
📋 Title: admin.shopify.com: Shopify Flow continues sending internal emails to a configured recipient after the staff author is removed
🔍 Reporter: abahack (Emmanuel Abah)
📋 Details:
└ 📊 Status: informative
└ ⚡ Severity: None
└ 🎯 CWE: Not Specified
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-03 18:50:06 UTC
└ 📝 Created: 2026-03-26 10:49:30 UTC
HackerOne
Shopify disclosed on HackerOne: admin.shopify.com: Shopify Flow...
The researcher reported that Shopify Flow workflows continue sending customer PII to email addresses after the staff user who created them is removed from the store. This is intended behavior -...
❤2👏1
🏦 Basecamp Report
⚡ Title: Any installed app can force immediate logout and persistent DOS of authenticated Basecamp sessions via unprotected exported StartActivity
🔍 Reporter: zerodaysec_xyz (Z)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Medium
└ 🎯 CWE: Improper Access Control - Generic
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-04 11:05:36 UTC
└ 📝 Created: 2026-05-27 08:46:53 UTC
⚡ Title: Any installed app can force immediate logout and persistent DOS of authenticated Basecamp sessions via unprotected exported StartActivity
🔍 Reporter: zerodaysec_xyz (Z)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Medium
└ 🎯 CWE: Improper Access Control - Generic
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-04 11:05:36 UTC
└ 📝 Created: 2026-05-27 08:46:53 UTC
HackerOne
Basecamp disclosed on HackerOne: Any installed app can force...
## Summary
Dear team. Our collaborative analysis and test on the latest Android Basecamp app (May 26 update) revealed that `com.basecamp.bc4.app.main.start.StartActivity` is declared...
Dear team. Our collaborative analysis and test on the latest Android Basecamp app (May 26 update) revealed that `com.basecamp.bc4.app.main.start.StartActivity` is declared...
❤4
🏦 AWS VDP Report
⚠️ Title: OS Command Injection in \`aws-cdk-lib\` NodejsFunction via Unsanitized \`OsCommand\` Helper \(Supply Chain RCE\)
🔍 Reporter: kaporia (Kaporia515)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: High
└ 🎯 CWE: OS Command Injection
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-06 17:48:30 UTC
└ 📝 Created: 2026-03-30 12:48:07 UTC
⚠️ Title: OS Command Injection in \`aws-cdk-lib\` NodejsFunction via Unsanitized \`OsCommand\` Helper \(Supply Chain RCE\)
🔍 Reporter: kaporia (Kaporia515)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: High
└ 🎯 CWE: OS Command Injection
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-06 17:48:30 UTC
└ 📝 Created: 2026-03-30 12:48:07 UTC
HackerOne
AWS VDP disclosed on HackerOne: OS Command Injection in...
**Asset:** `aws-cdk-lib` (npm package), source: https://github.com/aws/aws-cdk
**Severity:** High
**CWE:** CWE-78 (Improper Neutralization of Special Elements used in an OS Command, 'OS Command...
**Severity:** High
**CWE:** CWE-78 (Improper Neutralization of Special Elements used in an OS Command, 'OS Command...
❤4
🏦 AWS VDP Report
⚡ Title: Kiro IDE Stores Auth Tokens with World-Readable Permissions \(0644\)
🔍 Reporter: mistercloudsec (Sergio Garcia)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Medium
└ 🎯 CWE: Incorrect Default Permissions
└ 🔢 CVE: CVE-2026-11931
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-09 15:31:28 UTC
└ 📝 Created: 2026-03-26 20:58:40 UTC
⚡ Title: Kiro IDE Stores Auth Tokens with World-Readable Permissions \(0644\)
🔍 Reporter: mistercloudsec (Sergio Garcia)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Medium
└ 🎯 CWE: Incorrect Default Permissions
└ 🔢 CVE: CVE-2026-11931
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-09 15:31:28 UTC
└ 📝 Created: 2026-03-26 20:58:40 UTC
HackerOne
AWS VDP disclosed on HackerOne: Kiro IDE Stores Auth Tokens with...
> NOTE! Thanks for submitting a report to Amazon Web Services! Please replace *all* the [square] sections below with the pertinent details. Remember, the more detail you provide, the easier it is...
❤2👍1
🏦 SingleStore Report
⚠️ Title: SELECT ... INTO OUTFILE does not enforce the FILE WRITE privilege unprivileged arbitrary file write on the server
🔍 Reporter: bisht-ji (No name)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: High
└ 🎯 CWE: Missing Authorization
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-13 19:35:07 UTC
└ 📝 Created: 2026-06-03 20:54:07 UTC
⚠️ Title: SELECT ... INTO OUTFILE does not enforce the FILE WRITE privilege unprivileged arbitrary file write on the server
🔍 Reporter: bisht-ji (No name)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: High
└ 🎯 CWE: Missing Authorization
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-13 19:35:07 UTC
└ 📝 Created: 2026-06-03 20:54:07 UTC
HackerOne
SingleStore disclosed on HackerOne: SELECT ... INTO OUTFILE does...
A security researcher reported a privilege escalation vulnerability in SingleStore's self-managed database server where the SELECT...INTO OUTFILE command did not properly enforce the FILE WRITE...
❤1
🏦 AWS VDP Report
⚡ Title: bedrock-mantle.api.aws accepts Bedrock API keys outside the IAM Deny, CloudTrail signal, and invocation logging AWS publishes for Bedrock keys
🔍 Reporter: mistercloudsec (Sergio Garcia)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Medium
└ 🎯 CWE: Insecure Default Initialization of Resource
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-14 18:52:27 UTC
└ 📝 Created: 2026-04-28 21:50:53 UTC
⚡ Title: bedrock-mantle.api.aws accepts Bedrock API keys outside the IAM Deny, CloudTrail signal, and invocation logging AWS publishes for Bedrock keys
🔍 Reporter: mistercloudsec (Sergio Garcia)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Medium
└ 🎯 CWE: Insecure Default Initialization of Resource
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-14 18:52:27 UTC
└ 📝 Created: 2026-04-28 21:50:53 UTC
HackerOne
AWS VDP disclosed on HackerOne: bedrock-mantle.api.aws accepts...
> NOTE! Thanks for submitting a report to Amazon Web Services! Please replace *all* the [square] sections below with the pertinent details. Remember, the more detail you provide, the easier it is...
🏦 Basecamp Report
📝 Title: Stored XSS on Trix Editor version latest \(2.1.16\) - Sanitizer Bypass
🔍 Reporter: newbiefromcoma (jeeva)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Low
└ 🎯 CWE: Cross-site Scripting \(XSS\) - Stored
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-14 19:26:37 UTC
└ 📝 Created: 2026-03-02 22:01:38 UTC
📝 Title: Stored XSS on Trix Editor version latest \(2.1.16\) - Sanitizer Bypass
🔍 Reporter: newbiefromcoma (jeeva)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Low
└ 🎯 CWE: Cross-site Scripting \(XSS\) - Stored
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-14 19:26:37 UTC
└ 📝 Created: 2026-03-02 22:01:38 UTC
HackerOne
Basecamp disclosed on HackerOne: Stored XSS on Trix Editor version...
Trix version `2.1.16` is vulnerable to a Stored Cross-Site Scripting (XSS) flaw. The vulnerability arises from an unsafe interaction between Trix's custom `DOMPurify` configuration and its...
🏦 AWS VDP Report
⚡ Title: Bedrock AgentCore Starter Toolkit Creates Gateway IAM Roles Without Confused Deputy Protections
🔍 Reporter: mistercloudsec (Sergio Garcia)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Medium
└ 🎯 CWE: Incorrect Permission Assignment for Critical Resource
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-15 15:11:59 UTC
└ 📝 Created: 2026-03-27 19:33:14 UTC
⚡ Title: Bedrock AgentCore Starter Toolkit Creates Gateway IAM Roles Without Confused Deputy Protections
🔍 Reporter: mistercloudsec (Sergio Garcia)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Medium
└ 🎯 CWE: Incorrect Permission Assignment for Critical Resource
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-15 15:11:59 UTC
└ 📝 Created: 2026-03-27 19:33:14 UTC
HackerOne
AWS VDP disclosed on HackerOne: Bedrock AgentCore Starter Toolkit...
> NOTE! Thanks for submitting a report to Amazon Web Services! Please replace *all* the [square] sections below with the pertinent details. Remember, the more detail you provide, the easier it is...
❤2
🏦 GitHub Report
⚡ Title: Able to bypass authorization logic and gain more access then intended
🔍 Reporter: vaib25vicky (v1c7)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Medium
└ 🎯 CWE: Not Specified
└ 🔢 CVE: CVE-2026-9106
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-15 16:35:57 UTC
└ 📝 Created: 2026-05-05 07:30:36 UTC
⚡ Title: Able to bypass authorization logic and gain more access then intended
🔍 Reporter: vaib25vicky (v1c7)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Medium
└ 🎯 CWE: Not Specified
└ 🔢 CVE: CVE-2026-9106
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-15 16:35:57 UTC
└ 📝 Created: 2026-05-05 07:30:36 UTC
HackerOne
GitHub disclosed on HackerOne: Able to bypass authorization logic...
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could...
❤1
🏦 Rocket.Chat Report
⚡ Title: Stored XSS in Rocket.Chat HTML File Export — Unauthenticated Entry via LiveChat
🔍 Reporter: olidayw (Denis Rostilov)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Medium
└ 🎯 CWE: Cross-site Scripting \(XSS\) - Stored
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-16 05:02:04 UTC
└ 📝 Created: 2026-06-03 13:37:47 UTC
⚡ Title: Stored XSS in Rocket.Chat HTML File Export — Unauthenticated Entry via LiveChat
🔍 Reporter: olidayw (Denis Rostilov)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Medium
└ 🎯 CWE: Cross-site Scripting \(XSS\) - Stored
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-16 05:02:04 UTC
└ 📝 Created: 2026-06-03 13:37:47 UTC
HackerOne
Rocket.Chat disclosed on HackerOne: Stored XSS in Rocket.Chat HTML...
---
## Summary
Rocket.Chat's HTML file export feature (`rooms.export` API, `type=file`, `format=html`) writes message content and metadata directly into HTML output without any sanitization or...
## Summary
Rocket.Chat's HTML file export feature (`rooms.export` API, `type=file`, `format=html`) writes message content and metadata directly into HTML output without any sanitization or...
❤1
🏦 Monero Report
📝 Title: Restricted RPC leaks alternative block hashes via /get\_alt\_blocks\_hashes
🔍 Reporter: int0ha_ (Connor Carro)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Low
└ 🎯 CWE: Improper Access Control - Generic
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-20 00:15:10 UTC
└ 📝 Created: 2026-05-15 17:06:05 UTC
📝 Title: Restricted RPC leaks alternative block hashes via /get\_alt\_blocks\_hashes
🔍 Reporter: int0ha_ (Connor Carro)
📋 Details:
└ 📊 Status: resolved
└ ⚡ Severity: Low
└ 🎯 CWE: Improper Access Control - Generic
└ 🔢 CVE: None
⏰ Timeline:
└ 🔓 Disclosed: 2026-07-20 00:15:10 UTC
└ 📝 Created: 2026-05-15 17:06:05 UTC
HackerOne
Monero disclosed on HackerOne: Restricted RPC leaks alternative...
The `/get_alt_blocks_hashes` RPC endpoint was restricted to prevent unintended access to alternative block hashes. The endpoint had previously been unrestricted. The issue was assessed as low...
❤1