HackerOne Disclosed Reports - 2026-08-25

0 Replies, 7 Views

Logo
Medium
resolved

Hidden/restricted tags can be mutated through synonym ID paths without per-tag authorization


Bug reported by Minsun Kim was disclosed at August 26, 2026, 5:47 am   |   Insecure Direct Object Reference (IDOR)

A vulnerability was discovered in Discourse where a non-admin user with tag-editing permission could modify hidden or restricted tags by supplying their numeric IDs to the synonym creation and tag settings endpoints. Although the user could not view the hidden tags, the controller only authorized the visible target tag and did not re-check authorization for each synonym tag ID, allowing the non-admin user to update the synonym relationship of hidden tags.


Logo
Medium
resolved

Add labels to arbitrary issues/prs via Memex Bulk Update to compromise github actions label gating


Bug reported by ahacker1 was disclosed at August 25, 2026, 9:22 pm   |   Insecure Direct Object Reference (IDOR)

A vulnerability was identified in GitHub Enterprise Server that allowed a user with read access to a repository and write access to a project to modify issue and pull request metadata through the project. When adding an item to a project that already existed, column value updates were applied without verifying the actor's repository write permissions.


Logo
Low
resolved

@jitsi/docker-jitsi-meet: `/colibri-relay-ws/` unsafe nginx regex (OCTO relay configuration)


Bug reported by A3z4km3 was disclosed at August 25, 2026, 2:09 am   |   Cross-site Scripting (XSS) - Generic

An unsafe nginx regex pattern was discovered in the `/colibri-relay-ws/` location of the @jitsi/docker-jitsi-meet project. The regex `[a-zA-Z0-9-\\._]+` accepted arbitrary domain names and IP addresses for proxy_pass directives, allowing unauthenticated requests to be proxied to attacker-specified destinations. The vulnerable nginx location and associated relay WebSocket proxy configuration have been removed.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)