HackerOne Disclosed Reports - 2025-10-08

0 Replies, 158 Views

Logo
High
resolved

Pending invites remain valid even after the inviter is removed.


Bug reported by Mantosh Sah was disclosed at October 8, 2025, 3:51 am   |   Privilege Escalation

The pending invites created by a removed admin remained valid, and members already added by the removed admin remained in the team with admin privileges, even after the inviter was removed.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2025-10-08 - by hashXploiter - 10-09-2025, 12:30 PM



Users browsing this thread: