HackerOne Disclosed Reports - 2026-09-20

0 Replies, 6 Views

Logo
Low
resolved

Improper input validation in emoji field leads to sidebar UI denial of service


Bug reported by _dha was disclosed at September 20, 2026, 10:04 am   |   Business Logic Errors

A vulnerability was discovered in the Collectives app version 4.0.0 where the emoji field in the page emoji update endpoint did not properly validate user input. An attacker could have submitted an excessively long string including newline characters instead of a valid emoji, causing the sidebar layout to become broken.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)