resolved
HTML Injection in Contact Form Email Enables Phishing via Legitimate ████████ Infrastructure
Bug reported by Tenzai was disclosed at October 5, 2026, 11:34 am | Improper Output Neutralization for Logs
An HTML injection vulnerability was discovered in a contact form email endpoint. The firstName field was rendered as unescaped HTML in transactional confirmation emails sent via SendGrid. Anchor tags with inline styles were not sanitized and persisted in email clients, allowing styled links to be injected into legitimate branded emails. The endpoint accepted requests without authentication, CAPTCHA, or rate limiting. Image tags were stripped by the email pipeline, but anchor tags survived with attacker-controlled styling and href attributes that were rewritten through SendGrid's click tracking proxy.
resolved
Client-Side Denial of Service (DoS) via Memory Exhaustion on Password Reset Endpoint
Bug reported by Dipesh Pokhrel was disclosed at October 5, 2026, 2:23 am | Uncontrolled Resource Consumption
A client-side denial of service vulnerability was identified on a password reset endpoint. When the endpoint was accessed by an authenticated user, the browser automatically generated thousands of requests without user interaction, resulting in rapid memory exhaustion. The browser became unresponsive and crashed within minutes as memory usage continuously increased.

