HackerOne Disclosed Reports - 2026-08-01

0 Replies, 8 Views

Logo
Medium
resolved

Unauthenticated team "income/payments" export ignores donor privacy settings (hide_giving, hide_from_lists) and uses frozen visibility, exposing donat


Bug reported by Ali Khaled was disclosed at August 1, 2026, 12:27 pm   |  

A vulnerability was discovered in the unauthenticated team "income/payments" export feature of Liberapay. The vulnerability allowed an attacker to retrieve donor identity, exact donation amount, and donation dates for public donors, bypassing the donor's explicit privacy settings such as "hide_giving" and "hide_from_lists". The root cause was that the endpoint only honored the frozen visibility flag of the payment, and ignored the donor's current privacy settings as well as the recipient's opt-in gate. This resulted in the exposure of donations that the donor had since made private or secret.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2026-08-01 - by hashXploiter - Yesterday, 12:30 PM



Users browsing this thread: 1 Guest(s)