![]() |
|
HackerOne Disclosed Reports - 2026-09-24 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2026-09-24 (/Thread-HackerOne-Disclosed-Reports-2026-09-24) |
HackerOne disclosed reports - 2026-09-24 - hashXploiter - 09-25-2026
Low
resolved HackerOne Code sends live password-reset tokens to Segment in automatic page eventsBug reported by 1rhino2 was disclosed at September 24, 2026, 11:29 am | Insufficiently Protected Credentials A vulnerability was discovered in the HackerOne Code application, where opening a password-reset link automatically sent the complete unused 64-character reset token to Segment as the page loaded, before the reset form was submitted. The token was present in various fields of the Segment page event, which could potentially be accessed by anyone with read access to the Segment telemetry during the token's validity window. |