HackerOne Disclosed Reports - 2026-09-24

0 Replies, 19 Views

Logo
Low
resolved

HackerOne Code sends live password-reset tokens to Segment in automatic page events


Bug reported by 1rhino2 was disclosed at September 24, 2026, 11:29 am   |   Insufficiently Protected Credentials

A vulnerability was discovered in the HackerOne Code application, where opening a password-reset link automatically sent the complete unused 64-character reset token to Segment as the page loaded, before the reset form was submitted. The token was present in various fields of the Segment page event, which could potentially be accessed by anyone with read access to the Segment telemetry during the token's validity window.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)