04-02-2025, 06:00 PM
Critical
resolved
resolved
The /reports/:id.json endpoint discloses potentially sensitive user attributes when reporter summary is present
Bug reported by Avinash Kumar was disclosed at April 1, 2025, 6:23 pm | Information Disclosure
The /reports/:id.json endpoint disclosed potentially sensitive user attributes, including the reporter's email, OTP backup codes, phone number, graphql_secret_token, and t-shirt size when a reporter summary was present.