Dark C0d3rs

Full Version: HackerOne Disclosed Reports - 2026-10-02
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Logo
High
resolved

One-click cross-account JavaScript execution steals a victim write token through Turbo pagination and unattached Active Storage HTML


Bug reported by Pirikara was disclosed at October 2, 2026, 5:19 pm   |   Cross-site Scripting (XSS) - Reflected

A cross-account JavaScript execution vulnerability was discovered in a web application that allowed arbitrary code execution when a victim opened a crafted public board URL. An attacker with a separate account could leverage this vulnerability to steal the victim's write access token through a combination of flaws involving pagination parameter handling, unattached Active Storage HTML files, and inadequate MIME type validation. The stolen token was used to create, read, and delete data across the victim's accounts without authorization. The vulnerability required victim interaction through opening a single URL and affected confidentiality and integrity of victim data across unrelated accounts.